A flaw in Node.js HTTP/2 handling allows nghttp2_session_mem_send() to be called re-entrantly while nghttp2_session_mem_recv() is executing, resulting in a heap-use-after-free. Impact: Thank you, to hahahkim for reporting this vulnerability and thank you mcollina for fixing it.