CVE-2026-21710Patch(nodejs / enterprise_linux)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodejs enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770CWE-843

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • enterprise_linux_eus
  • node.js

Threat summary

  • Patch or workaround signal is available
  • 13 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-03-27); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Products
enterprise_linuxenterprise_linux_eusnode.js

5 versions affected across 3 products

Deep dive

Activity timeline13 mentions / 7d
01223Mentions · 2026-03-24: 2Mentions · 2026-03-25: 2Mentions · 2026-03-27: 3Mentions · 2026-03-30: 2Mentions · 2026-03-31: 2Mentions · 2026-04-09: 1Mentions · 2026-04-11: 1Patch / Workaround · 2026-03-24: 2Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-30: 2Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-11: 1Technical Details · 2026-03-24: 2Technical Details · 2026-03-25: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-09: 1Technical Details · 2026-04-11: 103-2403-2503-2703-3003-3104-0904-11
Signal classification3 categories
Patch
753.8%
Disclosure
430.8%
General
215.4%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-242
Patch2
2026-03-252
Disclosure1Patch1
2026-03-273
Disclosure1General2
2026-03-302
Patch2
2026-03-312
Disclosure2
2026-04-091
Patch1
2026-04-111
Patch1
Full discourse13 posts
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nodejs22 モジュール更新情報 22.22.2-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nodejs 22.22.2-1 この更新には脆弱性(CVE-2026-21637, CVE-2026-21710, CVE-2026-21713, CVE-2026-21714, CVE-2026-21717, CVE-2026-21715, CVE-202... https://kusanagi.tokyo/releases/23908/

    Post summary

    The release notes announce a module update that includes patches for multiple CVEs, but provide no further technical detail or exploitation information.

    01020120
    200 followersView on X
  • 山川和宏@とかち楽農技研@Mt1014snowman
    Disclosure

    エンジニア本業の人はどうやったら、こういった問題を特定しているのだろう? いきなり、落ちて1日対応していたけれど、見当違いなことばかりしていた Node.jsに深刻なDoS 脆弱性(CVE-2026-21710)など https://rocket-boys.co.jp/security-measures-lab/nodejs-severe-dos-vulnerabilities-cve-2026-21710/

    Post summary

    The post announces a severe DoS vulnerability in Node.js (CVE-2026-21710) and links to a blog article, but provides no PoC, exploit, or patch details.

    00020175
    285 followersView on X
  • Aun shah/ Ali memon@Aunshah102
    Patch

    Additionally, the update tackles CVE-2026-21710 by using null prototypes for headersDistinct/trailersDistinct in the http module, and CVE-2026-21716 and CVE-2026-21715, which add necessary permission checks to lib/fs/promises and realpath.native, 3/6

    Post summary

    The update fixes CVE‑2026‑21710, –21715, and –21716 by adding null prototypes for http headers and permission checks in filesystem modules.

    1000028
    17 followersView on X
  • Aun shah/ Ali memon@Aunshah102
    Patch

    @rafaelgss The release highlights include fixes for issues such as CVE-2026-21710, which involved using a null prototype for headersDistinct/trailersDistinct. This type of vulnerability can often lead to unexpected behavior or potential security bypasses. 3/17

    Post summary

    A release notes the application of a fix for CVE‑2026‑21710, outlining the issue with a null prototype for headers, and confirms patching.

    1000026
    17 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-21710 A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.he… https://www.cve.org/CVERecord?id=CVE-2026-21710 ----- Traducción: CVE-2026-21710 Un … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-21710, describing a Node.js HTTP request handling flaw that triggers an uncaught TypeError when a header named '__proto__' is accessed, but provides no PoC, exploit code, patch, or exploitation evidence.

    0001028
    65 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Node.js ❗ CVE-2026-21710 ❗ CVE-2026-21637 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-node-js/ https://t.co/7nU2cSliLt

    Post summary

    The tweet lists two Node.js CVE identifiers and provides a link to a CERT page for more information, but contains no specific technical details, PoC, or exploit information.

    00010112
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21710 A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.he… https://www.cve.org/CVERecord?id=CVE-2026-21710

    Post summary

    A Node.js HTTP request handling flaw triggers an uncaught TypeError when a request contains a `__proto__` header, potentially affecting applications that access the request headers.

    00000165
    56.9K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nodejs22 Module Update 22.22.2-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: nodejs 22.22.2-1 This update includes support for vulnerability(CVE-2026-21637, CVE-2026-21710, CVE-2026-21713, CVE-2026-21714,... https://kusanagi.tokyo/en/releases/23909/

    Post summary

    The KUSANAGI nodejs22 module update 22.22.2-1 includes patches for CVE‑2026‑21637, CVE‑2026‑21710, CVE‑2026‑21713, and CVE‑2026‑21714, but no proof‑of‑concept, exploit, or active exploitation details are provided.

    0000065
    200 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    Node.jsに深刻なDoS 脆弱性(CVE-2026-21710)など https://rocket-boys.co.jp/security-measures-lab/nodejs-severe-dos-vulnerabilities-cve-2026-21710/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The headline references a severe DoS vulnerability (CVE‑2026‑21710) in Node.js, but provides no additional technical details or actionable information.

    00000127
    364 followersView on X
  • ティー🌐@TeeTheta
    Patch

    対処された脆弱性(22.x対象8件) CVE-2026-21637 (High) CVE-2026-21710 (High) CVE-2026-21713 (Medium) CVE-2026-21714 (Medium) CVE-2026-21717 (Medium) CVE-2026-21715 (Low) CVE-2026-21716 (Low) undici 6.24.1/7.24.4 への依存更新

    Post summary

    A patch notice informs that eight CVEs affecting version 22.x have been fixed by updating the undici dependency to 6.24.1/7.24.4, with no PoC, exploit, or detailed vulnerability information provided.

    0000071
    1 followersView on X
  • motch | セキュリティ🛡️@motch_dev
    Disclosure

    今回のNode.jsの影響度HIGHの脆弱性について詳細📝 1. TLS処理におけるリモートDoS(CVE-2026-21637の不完全な修正) * 脆弱性の概要: TLS通信(HTTPSなどの暗号化通信)を確立する際の「サーバー名表示(SNI)」の処理に、エラーを安全に処理する仕組み(try/catch)が欠けていた問題です。以前のパッチの不完全な修正が原因で発生しました。 * 発生メカニズム: サーバーが予期しない不正なサーバー名(入力)を受け取った際、内部の SNICallback 関数が同期的な例外(エラー)をスローします。しかし、このエラーをキャッチする防御網が欠落していたため、TLSのエラー処理をすり抜けてしまいます。 * 影響: エラーが「捕捉されない例外(Uncaught Exception)」として伝播し、Node.jsのプロセスそのものをクラッシュさせます。攻撃者は不正なSNIを含むリクエストを送りつけるだけで、容易にサーバーをダウンさせることができます。 2. HTTPヘッダー __proto__ 経由のDoS(CVE-2026-21710) * 脆弱性の概要: HTTPリクエストのヘッダー処理におけるバグです。特定のヘッダー名と内部プロパティの組み合わせによって、捕捉できない型エラー(TypeError)が発生します。 * 発生メカニズム: 攻撃者が __proto__ という名前の悪意あるHTTPヘッダーを含むリクエストを送信し、アプリケーション側が req.headersDistinct (同名ヘッダーの値を配列で取得するAPI)にアクセスした際に発火します。内部でJavaScriptの仕様(プロトタイプチェーン)が意図せず解釈され、配列ではないオブジェクトに対して配列用の追加処理(.push())を行おうとして致命的なエラーになります。 * 影響: この例外はプロパティにアクセスした瞬間に同期的に発生するため、通常のエラーハンドリング(イベントリスナーなど)では捕捉できません。結果として、これもNode.jsプロセスを即座にクラッシュさせ、サービス停止を引き起こします。

    Post summary

    The post provides technical details on two high‑impact Node.js DoS vulnerabilities (CVE‑2026‑21637 and CVE‑2026‑21710) but offers no PoC, exploit code, active exploitation evidence, or patch information.

    0000071
    251 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v24.14.1 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリースです。 • undiciを7.24.4に更新 • npmを11.11.0にアップグレード • V8の依存関係を更新 🔧 重要な修正: • (CVE-2026-21710) headersDistinct/trailersDistinctにnullプロトタイプを使用 • (CVE-2026-21637) SNICallback呼び出しをtry/catchでラップ • (CVE-2026-21717) 配列インデックスのハッシュ衝突をテスト • (CVE-2026-21713) Web Cryptography HMACおよびKMACでタイミング安全な比較を使用 • (CVE-2026-21714) NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 • (CVE-2026-21712) 異なるURL形式でのURLクラッシュを処理 • (CVE-2026-21716) lib/fs/promisesにパーミッションチェックを含める • (CVE-2026-21715) realpath.nativeにパーミッションチェックを追加 #GitHub #Release #Node.js

    Post summary

    Node.js v24.14.1 is released as a security patch fixing a list of CVEs with brief technical descriptions, reinforcing the platform’s safety.

    0000066
    2 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v25.8.2 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリース。 🔧 重要な修正: • SNICallbackの呼び出しをtry/catchでラップ (CVE-2026-21637) - 高 • headersDistinct/trailersDistinctにnullプロトタイプを使用 (CVE-2026-21710) - 高 • pipe_wrap.ccにパーミッションチェックを追加 (CVE-2026-21711) - 中 • 異なるURL形式でのURLクラッシュを処理 (CVE-2026-21712) - 中 • Web Cryptography HMACおよびKMACでタイミングセーフな比較を使用 (CVE-2026-21713) - 中 • NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 (CVE-2026-21714) - 中 • 配列インデックスハッシュ衝突のテスト (CVE-2026-21717) - 中 • realpath.nativeにパーミッションチェックを追加 (CVE-2026-21715) - 低 • lib/fs/promisesにパーミッションチェックを追加 (CVE-2026-21716) - 低 #GitHub #Release #Node.js

    Post summary

    Node.js v25.8.2 is a security patch release fixing multiple CVEs with detailed CVSS‑style severity ratings, signaling a focused update rather than exploitation or PoC activity.

    0000049
    2 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
OSredhatenterprise_linux_eus10.0--
OSredhatenterprise_linux_eus9.4--
OSredhatenterprise_linux_eus9.6--

Explore more