http2: cap originSet size to prevent unbounded memory growth
A malicious HTTP/2 server can send repeated ORIGIN frames with unique
origins, causing unbounded growth of the client-side originSet for the
lifetime of the session. Cap the set at 128 entries; once full, new
origins from ORIGIN frames are silently dropped.
Ref: https://hackerone.com/reports/
3676863
PR-URL: https://github.com/nodejs-private/node-private/pull/855
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
CVE-ID: CVE-2026-48619
Refs: https://hackerone.com/reports/
3676863
origin: backport, https://github.com/nodejs/node/commit/
c79968e108002c2394bdb9e9cefb2c8c8cc202f8
Gbp-Pq: Topic sec
Gbp-Pq: Name CVE-2026-48619.patch