CVE-2026-21716Patch(nodejs / node.js)

LOWCVSS 3.3 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodejs node.js systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patched. As a result, code running under `--permission` with restricted `--allow-fs-write` can still use promise-based `FileHandle` methods to modify file permissions and ownership on already-open file descriptors, bypassing the intended write restrictions. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-write` is intentionally restricted.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 7 signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 2 mentions (2026-03-24); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
node.js

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-03-24: 2Mentions · 2026-03-25: 1Mentions · 2026-03-31: 2Mentions · 2026-04-09: 1Mentions · 2026-04-11: 1Mentions · 2026-04-15: 1Patch / Workaround · 2026-03-24: 2Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-11: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-03-24: 2Technical Details · 2026-03-25: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-09: 1Technical Details · 2026-04-11: 103-2403-2503-3104-0904-1104-15
Signal classification2 categories
Patch
675.0%
Disclosure
225.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-242
Patch2
2026-03-251
Patch1
2026-03-312
Disclosure2
2026-04-091
Patch1
2026-04-111
Patch1
2026-04-151
Patch1
Full discourse8 posts
  • Aun shah/ Ali memon@Aunshah102
    Patch

    Additionally, the update tackles CVE-2026-21710 by using null prototypes for headersDistinct/trailersDistinct in the http module, and CVE-2026-21716 and CVE-2026-21715, which add necessary permission checks to lib/fs/promises and realpath.native, 3/6

    Post summary

    The update patches CVE-2026-21710, CVE-2026-21715, and CVE-2026-21716 by applying null prototypes to specific HTTP headers and adding required permission checks to fs promises and realpath.native.

    1000028
    17 followersView on X
  • Aun shah/ Ali memon@Aunshah102
    Patch

    @rafaelgss Lower severity issues were also patched, including permission checks on lib/fs/promises (CVE-2026-21716) and realpath.native (CVE-2026-21715), both contributed by RafaelGSS. 9/17

    Post summary

    The tweet announces that CVE-2026-21716 and CVE-2026-21715, both permission‑check issues in lib/fs/promises and realpath.native, have been patched by the contributor RafaelGSS, indicating a release of security updates for lower‑severity bugs.

    1000023
    17 followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-21716 is in the Security Update Guide, even if the juicy details aren’t public yet. Translation: patch now, investigate later—because Windows love surprises. https://windowsforum.com/threads/cve-2026-21716-what-microsoft-security-update-guide-means-for-windows-defenders.413508/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #VulnerabilityTriage #EnterprisePatchManagement #MicrosoftSecurityUpdates #Cve202621716

    Post summary

    The post highlights that CVE-2026-21716 is listed in the Microsoft Security Update Guide and urges users to patch immediately despite lacking detailed vulnerability information.

    0000080
    1.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-21716 An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their call… https://www.cve.org/CVERecord?id=CVE-2026-21716 ----- Traducción: CVE-2026-21716 Una… http://infoflow.cloud`

    Post summary

    The tweet identifies CVE-2026-21716, noting it as an incomplete fix that leaves permission checks missing on certain functions, and links to the official CVE record.

    0000024
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21716 An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their call… https://www.cve.org/CVERecord?id=CVE-2026-21716

    Post summary

    The post reports an incomplete fix for CVE-2024-36137, noting that FileHandle.chmod() and FileHandle.chown() lack permission checks, but it does not provide PoC, exploit, or active exploitation details.

    00000153
    56.9K followersView on X
  • ティー🌐@TeeTheta
    Patch

    対処された脆弱性(22.x対象8件) CVE-2026-21637 (High) CVE-2026-21710 (High) CVE-2026-21713 (Medium) CVE-2026-21714 (Medium) CVE-2026-21717 (Medium) CVE-2026-21715 (Low) CVE-2026-21716 (Low) undici 6.24.1/7.24.4 への依存更新

    Post summary

    The text announces eight CVEs for version 22.x, provides severity ratings, and notes that the issue is mitigated by updating the dependency to undici 6.24.1/7.24.4.

    0000071
    1 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v24.14.1 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリースです。 • undiciを7.24.4に更新 • npmを11.11.0にアップグレード • V8の依存関係を更新 🔧 重要な修正: • (CVE-2026-21710) headersDistinct/trailersDistinctにnullプロトタイプを使用 • (CVE-2026-21637) SNICallback呼び出しをtry/catchでラップ • (CVE-2026-21717) 配列インデックスのハッシュ衝突をテスト • (CVE-2026-21713) Web Cryptography HMACおよびKMACでタイミング安全な比較を使用 • (CVE-2026-21714) NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 • (CVE-2026-21712) 異なるURL形式でのURLクラッシュを処理 • (CVE-2026-21716) lib/fs/promisesにパーミッションチェックを含める • (CVE-2026-21715) realpath.nativeにパーミッションチェックを追加 #GitHub #Release #Node.js

    Post summary

    Node.js released v24.14.1 with security patches that address several CVEs, including fixes for prototype handling, permission checks, and buffer error handling. All listed CVEs are documented as resolved by this update.

    0000066
    2 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v25.8.2 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリース。 🔧 重要な修正: • SNICallbackの呼び出しをtry/catchでラップ (CVE-2026-21637) - 高 • headersDistinct/trailersDistinctにnullプロトタイプを使用 (CVE-2026-21710) - 高 • pipe_wrap.ccにパーミッションチェックを追加 (CVE-2026-21711) - 中 • 異なるURL形式でのURLクラッシュを処理 (CVE-2026-21712) - 中 • Web Cryptography HMACおよびKMACでタイミングセーフな比較を使用 (CVE-2026-21713) - 中 • NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 (CVE-2026-21714) - 中 • 配列インデックスハッシュ衝突のテスト (CVE-2026-21717) - 中 • realpath.nativeにパーミッションチェックを追加 (CVE-2026-21715) - 低 • lib/fs/promisesにパーミッションチェックを追加 (CVE-2026-21716) - 低 #GitHub #Release #Node.js

    Post summary

    Node.js v25.8.2 is a security patch release fixing multiple CVEs with specified severity, and no proof‑of‑concept or active exploitation details are mentioned.

    0000049
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js---

Explore more