CVE-2026-21713Patch(nodejs / node.js)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodejs node.js systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-208

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 2 mentions (2026-03-24); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
node.js

Deep dive

Activity timeline10 mentions / 6d
01122Mentions · 2026-03-24: 2Mentions · 2026-03-25: 1Mentions · 2026-03-30: 2Mentions · 2026-03-31: 2Mentions · 2026-04-09: 2Mentions · 2026-04-11: 1Patch / Workaround · 2026-03-24: 2Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-30: 2Patch / Workaround · 2026-04-09: 2Patch / Workaround · 2026-04-11: 1Technical Details · 2026-03-24: 2Technical Details · 2026-03-31: 2Technical Details · 2026-04-09: 1Technical Details · 2026-04-11: 103-2403-2503-3003-3104-0904-11
Signal classification3 categories
Patch
770.0%
Disclosure
220.0%
General
110.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-242
Patch2
2026-03-251
Patch1
2026-03-302
Patch2
2026-03-312
Disclosure2
2026-04-092
General1Patch1
2026-04-111
Patch1
Full discourse10 posts
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nodejs22 モジュール更新情報 22.22.2-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nodejs 22.22.2-1 この更新には脆弱性(CVE-2026-21637, CVE-2026-21710, CVE-2026-21713, CVE-2026-21714, CVE-2026-21717, CVE-2026-21715, CVE-202... https://kusanagi.tokyo/releases/23908/

    Post summary

    The Kusakagi Node.js module update for 9.x includes patches for several CVE‑2026 vulnerabilities, indicating a patch release rather than a disclosure of new exploits.

    01020120
    200 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21713 A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional … https://www.cve.org/CVERecord?id=CVE-2026-21713

    Post summary

    The post announces a Node.js HMAC timing‑leak vulnerability (CVE‑2026‑21713) without providing PoC, exploit, or patch details.

    00020171
    57.6K followersView on X
  • Aun shah/ Ali memon@Aunshah102
    Patch

    This release includes fixes for CVE-2026-21717, a critical array index hash collision, and CVE-2026-21713, which improves the security of Web Cryptography HMAC and KMAC operations through timing-safe comparisons. 2/6

    Post summary

    The release notes announce fixes for two CVEs, providing brief technical descriptions and confirming a patch is available.

    1000043
    17 followersView on X
  • Aun shah/ Ali memon@Aunshah102
    Patch

    @rafaelgss Filip Skokan contributed a fix for CVE-2026-21713, implementing timing-safe comparisons in Web Cryptography HMAC and KMAC operations, which is essential for cryptographic security. 6/17

    Post summary

    The text announces that a bug fix for CVE‑2026‑21713 has been contributed, addressing timing‑attack vulnerability in Web Cryptography HMAC/KMAC functions.

    1000032
    17 followersView on X
  • WindowsForum@windowsforum
    General

    🛠️ So Microsoft’s CVE is “exploit only if the universe aligns.” Great. Meanwhile defenders get the fun job: tighten configs, hunt exposure, and pray their network layout isn’t the key. https://windowsforum.com/threads/cve-2026-21713-conditional-exploitability-and-what-defenders-should-do.411257/ #MicrosoftSecurity #VulnerabilityManagement #Cve202621713

    Post summary

    The tweet references Microsoft’s CVE‑2026‑21713 with conditional exploitability and advises defenders to tighten configurations, but it does not provide a PoC, exploit code, active exploitation evidence, technical details, or a patch.

    0000025
    1.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-21713 A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional … https://www.cve.org/CVERecord?id=CVE-2026-21713 ----- Traducción: CVE-2026-21713 Una… http://infoflow.cloud`

    Post summary

    This tweet announces the new CVE-2026-21713, describing a timing information leak due to non‑constant‑time HMAC verification in Node.js.

    0000026
    65 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nodejs22 Module Update 22.22.2-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: nodejs 22.22.2-1 This update includes support for vulnerability(CVE-2026-21637, CVE-2026-21710, CVE-2026-21713, CVE-2026-21714,... https://kusanagi.tokyo/en/releases/23909/

    Post summary

    The Kusanagi Node.js module update 22.22.2-1 provides patches for multiple CVEs, addressing the vulnerabilities without presenting exploit code or evidence of active attacks.

    0000065
    200 followersView on X
  • ティー🌐@TeeTheta
    Patch

    対処された脆弱性(22.x対象8件) CVE-2026-21637 (High) CVE-2026-21710 (High) CVE-2026-21713 (Medium) CVE-2026-21714 (Medium) CVE-2026-21717 (Medium) CVE-2026-21715 (Low) CVE-2026-21716 (Low) undici 6.24.1/7.24.4 への依存更新

    Post summary

    The post announces that eight CVEs have been addressed by updating the 'undici' dependency to versions 6.24.1 and 7.24.4.

    0000071
    1 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v24.14.1 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリースです。 • undiciを7.24.4に更新 • npmを11.11.0にアップグレード • V8の依存関係を更新 🔧 重要な修正: • (CVE-2026-21710) headersDistinct/trailersDistinctにnullプロトタイプを使用 • (CVE-2026-21637) SNICallback呼び出しをtry/catchでラップ • (CVE-2026-21717) 配列インデックスのハッシュ衝突をテスト • (CVE-2026-21713) Web Cryptography HMACおよびKMACでタイミング安全な比較を使用 • (CVE-2026-21714) NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 • (CVE-2026-21712) 異なるURL形式でのURLクラッシュを処理 • (CVE-2026-21716) lib/fs/promisesにパーミッションチェックを含める • (CVE-2026-21715) realpath.nativeにパーミッションチェックを追加 #GitHub #Release #Node.js

    Post summary

    Node.js v24.14.1 has been released as a patch update, addressing several CVEs with detailed fixes for each vulnerability.

    0000066
    2 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v25.8.2 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリース。 🔧 重要な修正: • SNICallbackの呼び出しをtry/catchでラップ (CVE-2026-21637) - 高 • headersDistinct/trailersDistinctにnullプロトタイプを使用 (CVE-2026-21710) - 高 • pipe_wrap.ccにパーミッションチェックを追加 (CVE-2026-21711) - 中 • 異なるURL形式でのURLクラッシュを処理 (CVE-2026-21712) - 中 • Web Cryptography HMACおよびKMACでタイミングセーフな比較を使用 (CVE-2026-21713) - 中 • NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 (CVE-2026-21714) - 中 • 配列インデックスハッシュ衝突のテスト (CVE-2026-21717) - 中 • realpath.nativeにパーミッションチェックを追加 (CVE-2026-21715) - 低 • lib/fs/promisesにパーミッションチェックを追加 (CVE-2026-21716) - 低 #GitHub #Release #Node.js

    Post summary

    Node.js v25.8.2 release patches multiple high‑severity CVEs, providing detailed fix information without evidence of exploitation or PoC.

    0000049
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js---

Explore more