Security vulnerability affects the apache-superset package. A malformed HTTP/2 HEADERS frame with oversized, invalid HPACK data can cause Node.
HTTP/2 HEADERS
HPACK
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-UP28744.json"