CVE-2026-21711Disclosure(nodejs / node.js)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch nodejs node.js systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose local IPC endpoints, allowing communication with other processes on the same host outside of the intended network restriction boundary. This vulnerability affects Node.js **25.x** processes using the Permission Model where `--allow-net` is intentionally omitted to restrict network access. Note that `--allow-net` is currently an experimental feature.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-31)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
node.js

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-24: 1Mentions · 2026-03-31: 2Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-31: 203-2403-31
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-241
Patch1
2026-03-312
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-21711 A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable … https://www.cve.org/CVERecord?id=CVE-2026-21711 ----- Traducción: CVE-2026-21711 Un … http://infoflow.cloud`

    Post summary

    The tweet announces the discovery of CVE-2026-21711, a Node.js permission model flaw affecting Unix Domain Sockets, without providing patches, proof of concept, or evidence of active exploitation.

    0000022
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21711 A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable … https://www.cve.org/CVERecord?id=CVE-2026-21711

    Post summary

    Node.js permission model flaw allows Unix Domain Socket server operations to bypass required permission checks, as documented in CVE‑2026‑21711.

    00000177
    56.9K followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v25.8.2 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリース。 🔧 重要な修正: • SNICallbackの呼び出しをtry/catchでラップ (CVE-2026-21637) - 高 • headersDistinct/trailersDistinctにnullプロトタイプを使用 (CVE-2026-21710) - 高 • pipe_wrap.ccにパーミッションチェックを追加 (CVE-2026-21711) - 中 • 異なるURL形式でのURLクラッシュを処理 (CVE-2026-21712) - 中 • Web Cryptography HMACおよびKMACでタイミングセーフな比較を使用 (CVE-2026-21713) - 中 • NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 (CVE-2026-21714) - 中 • 配列インデックスハッシュ衝突のテスト (CVE-2026-21717) - 中 • realpath.nativeにパーミッションチェックを追加 (CVE-2026-21715) - 低 • lib/fs/promisesにパーミッションチェックを追加 (CVE-2026-21716) - 低 #GitHub #Release #Node.js

    Post summary

    Node.js v25.8.2 is a patch release addressing multiple CVEs, including high‑severity issues, without any reported PoC, exploit tool, or active exploitation.

    0000049
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js---

Explore more