Node.js是Node.js基金会开源的一个跨平台的 JavaScript 运行时环境。 Node.js 26.5.0及之前版本、24.18.0及之前版本和22.23.1及之前版本存在资源管理错误漏洞,该漏洞源于HTTP/2处理缺陷,允许在执行nghttp2_session_mem_recv()时重入调用nghttp2_session_mem_send(),导致堆释放后重用,可能造成拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58045 | nodejs node 资源管理错误漏洞 | |
| CVE-2026-58041 | Node.js 竞争条件问题漏洞 | |
| CVE-2026-58042 | nodejs node 资源管理错误漏洞 | |
| CVE-2026-58044 | nodejs node 输入验证错误漏洞 | |
| CVE-2026-56846 | Node.js 资源管理错误漏洞 |
No comments yet