Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.
#NodeJS #CVE202656848 #HTTP2 #UseAfterFree #Vulnerability #InfoSec
https://securityonline.info/nodejs-july-2026-security-release/?utm_source=mastodon&utm_medium=jetpack_social
About This Hashtag
#http2
3 posts
Last used Jul 29
#http2
3 posts· Last used Jul 29
Following some discussions during #IETF last week (in the hallway and on various mailing lists), the awesome #IPvFoo extension now shows in Mozilla #FireFox if connections used H1, H2, or H3, not just IPv4-vs-IPv6! This is helpful for seeing how that angle of Happy Eyeballs works.
(It would work in the Chrome version as well but the interface for getting at this info is broken and always returns H1.)
Note that if the connection starts with H2 but then switches to H3 for later objects on the hostname (eg, if you have an Alt-Svc record) then it will show H3 rather than H2.
https://addons.mozilla.org/en-US/firefox/addon/ipvfoo/
#QUIC #HTTP2 #HTTP3 #IPv6 #HappyEyeballs
An HTTP/2 DoS vulnerability lets unauthenticated attackers exhaust server memory via stalled flow control. CVE-2026-59762 and CVE-2026-59173 are patched.
#HTTP2 #DoS #DenialOfService #CVE202659762 #CVE202659173 #FlowControl #InfoSec #PatchNow
http://securityonline.info/http2-dos-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
You've seen all posts