]> dgit.raspbian.org Git - nodejs.git/commit
http2: cap originSet size to prevent unbounded memory growth
authorMatteo Collina <hello@matteocollina.com>
Sun, 19 Apr 2026 14:48:43 +0000 (16:48 +0200)
committerBastien Roucariès <rouca@debian.org>
Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)
commit2aacec2ff42b32c52a5cdc224b6d92fa6297542e
tree0378c0b75c341555bb07adee220fbeb34110d28e
parent80d0539c37c352467670852992c5a870293e78ab
http2: cap originSet size to prevent unbounded memory growth

A malicious HTTP/2 server can send repeated ORIGIN frames with unique
origins, causing unbounded growth of the client-side originSet for the
lifetime of the session. Cap the set at 128 entries; once full, new
origins from ORIGIN frames are silently dropped.

Ref: https://hackerone.com/reports/3676863
PR-URL: https://github.com/nodejs-private/node-private/pull/855
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
CVE-ID: CVE-2026-48619
Refs: https://hackerone.com/reports/3676863
origin: backport, https://github.com/nodejs/node/commit/c79968e108002c2394bdb9e9cefb2c8c8cc202f8

Gbp-Pq: Topic sec
Gbp-Pq: Name CVE-2026-48619.patch
doc/api/errors.md
doc/api/http2.md
lib/internal/errors.js
lib/internal/http2/core.js
test/parallel/test-http2-origin-set-max-size.mjs [new file with mode: 0644]