CVE-2026-21712Patch(nodejs / node.js)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodejs node.js systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-24); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
node.js

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-24: 2Mentions · 2026-03-31: 2Mentions · 2026-04-09: 1Patch / Workaround · 2026-03-24: 2Patch / Workaround · 2026-04-09: 1Technical Details · 2026-03-24: 2Technical Details · 2026-03-31: 2Technical Details · 2026-04-09: 103-2403-3104-09
Signal classification3 categories
Patch
360.0%
Disclosure
120.0%
General
120.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-242
Patch2
2026-03-312
Disclosure1General1
2026-04-091
Patch1
Full discourse5 posts
  • Aun shah/ Ali memon@Aunshah102
    Patch

    @rafaelgss RafaelGSS also contributed fixes for CVE-2026-21714 and CVE-2026-21712, addressing NGHTTP2_ERR_FLOW_CONTROL errors and URL parsing crashes respectively. 7/17

    Post summary

    The tweet announces that RafaelGSS added fixes for CVE-2026-21714 (NGHTTP2_ERR_FLOW_CONTROL) and CVE-2026-21712 (URL parsing crashes).

    1000022
    17 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-21712 A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) contain… https://www.cve.org/CVERecord?id=CVE-2026-21712 ----- Traducción: CVE-2026-21712 Una… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-21712, a Node.js URL parsing flaw that triggers an assertion failure on malformed IDNs, providing basic technical details but no PoC, exploit, patch, or evidence of active exploitation.

    0000030
    65 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-21712 A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) contain… https://www.cve.org/CVERecord?id=CVE-2026-21712

    Post summary

    The text provides a brief technical description of CVE‑2026‑21712’s flaw in Node.js URL handling, but offers no details on exploits, patches, or active use.

    00000214
    56.9K followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v24.14.1 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリースです。 • undiciを7.24.4に更新 • npmを11.11.0にアップグレード • V8の依存関係を更新 🔧 重要な修正: • (CVE-2026-21710) headersDistinct/trailersDistinctにnullプロトタイプを使用 • (CVE-2026-21637) SNICallback呼び出しをtry/catchでラップ • (CVE-2026-21717) 配列インデックスのハッシュ衝突をテスト • (CVE-2026-21713) Web Cryptography HMACおよびKMACでタイミング安全な比較を使用 • (CVE-2026-21714) NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 • (CVE-2026-21712) 異なるURL形式でのURLクラッシュを処理 • (CVE-2026-21716) lib/fs/promisesにパーミッションチェックを含める • (CVE-2026-21715) realpath.nativeにパーミッションチェックを追加 #GitHub #Release #Node.js

    Post summary

    Node.js v24.14.1 was released with security patches for multiple CVEs, covering issues from prototype usage to URL handling and permission checks.

    0000066
    2 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v25.8.2 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリース。 🔧 重要な修正: • SNICallbackの呼び出しをtry/catchでラップ (CVE-2026-21637) - 高 • headersDistinct/trailersDistinctにnullプロトタイプを使用 (CVE-2026-21710) - 高 • pipe_wrap.ccにパーミッションチェックを追加 (CVE-2026-21711) - 中 • 異なるURL形式でのURLクラッシュを処理 (CVE-2026-21712) - 中 • Web Cryptography HMACおよびKMACでタイミングセーフな比較を使用 (CVE-2026-21713) - 中 • NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 (CVE-2026-21714) - 中 • 配列インデックスハッシュ衝突のテスト (CVE-2026-21717) - 中 • realpath.nativeにパーミッションチェックを追加 (CVE-2026-21715) - 低 • lib/fs/promisesにパーミッションチェックを追加 (CVE-2026-21716) - 低 #GitHub #Release #Node.js

    Post summary

    Node.js v25.8.2 was released as a security patch, addressing multiple CVEs with detailed fix notes and severity levels.

    0000049
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js---

Explore more