Supply Chain Security qs 6.16.0: two denial-of-service flaws in a widely used Node.js parser
CVE-2026-82417 and CVE-2026-82562 show how a hostile object shape and commas under a[] can violate parser assumptions, causing exceptions or memory pressure.