CVE-2026-21717Disclosure(nodejs / node.js)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodejs node.js systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process. The most common trigger is any endpoint that calls `JSON.parse()` on attacker-controlled input, as JSON parsing automatically internalizes short strings into the affected hash table. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-328

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 7d ago at 2 mentions (2026-03-24); latest day: 1
  • 11 total mentions across 8 days

Affected systems

Vendors
Products
node.js

Deep dive

Activity timeline11 mentions / 8d
01122Mentions · 2026-03-24: 2Mentions · 2026-03-25: 2Mentions · 2026-03-30: 1Mentions · 2026-03-31: 2Mentions · 2026-04-09: 1Mentions · 2026-04-11: 1Mentions · 2026-04-13: 1Mentions · 2026-05-05: 1Patch / Workaround · 2026-03-24: 2Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-04-11: 1Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-05-05: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-09: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-13: 1Technical Details · 2026-05-05: 103-2403-2503-3003-3104-0904-1104-1305-05
Signal classification2 categories
Disclosure
654.5%
Patch
545.5%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-242
Patch2
2026-03-252
Disclosure1Patch1
2026-03-301
Patch1
2026-03-312
Disclosure2
2026-04-091
Disclosure1
2026-04-111
Patch1
2026-04-131
Disclosure1
2026-05-051
Disclosure1
Full discourse11 posts
  • Node.js@nodejs
    Disclosure

    In CVE-2026-21717, the root cause lied in the unseeded hash V8 used for integer-looking strings, which needs to be quickly reversible to the original integer to maintain V8's performance optimizations. This poses a unique challenge not present in typical string hashing.

    Post summary

    The post discloses technical details of CVE-2026-21717, focusing on the unseeded hash V8 for integer‑looking strings and the challenges it creates, without mentioning exploits, patches, or active attacks.

    100611.7K
    908.4K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nodejs22 モジュール更新情報 22.22.2-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nodejs 22.22.2-1 この更新には脆弱性(CVE-2026-21637, CVE-2026-21710, CVE-2026-21713, CVE-2026-21714, CVE-2026-21717, CVE-2026-21715, CVE-202... https://kusanagi.tokyo/releases/23908/

    Post summary

    The release notes announce that kusanagi-nodejs22 has been updated to version 22.22.2‑1, which resolves several CVE‑2026 vulnerabilities.

    01020120
    200 followersView on X
  • HeroDevs@herodevs
    Disclosure

    🚨 New CVE Alert: CVE-2026-21717 (Node.js) A medium-severity HashDoS vulnerability has been discovered in Node.js's V8 engine. The issue: integer-like strings are hashed to their numeric value, making hash collisions predictable and exploitable. What this means: → Attackers can craft inputs that degrade hash table operations from O(1) to O(n) → No authentication required — but high attack complexity (crafting collision payloads takes knowledge of the hashing algorithm) → Affects Node.js v20.x, v22.x, v24.x, and v25.x → Worst case: event loop blocking and sustained CPU consumption, leading to denial of service Patching is straightforward if you're on a supported version — fixes landed in v20.20.2, v22.22.2, v24.14.1, and v25.8.2. But if you're running Node.js v12, v14, v16, or v18 — all past end-of-life — no official patch is coming. New CVEs don't stop. Official patches do. It's the kind of issue that seems small at first, until you realize you've been wandering into danger without the right gear. ⚔ That's where HeroDevs Never-Ending Support (NES) for Node.js comes in, continuing to backport CVE fixes for EOL versions so your applications stay protected while you plan your migration. Because performance degradation is a headache. Unpatched, exploitable performance degradation is a liability. #NodeJS #CVE #AppSec #OpenSourceSecurity #DevSecOps #HeroDevs

    Post summary

    A new HashDoS vulnerability (CVE‑2026‑21717) in Node.js V8 allows attackers to degrade hash performance and potentially cause denial of service; patches are available for supported releases and backported fixes exist for legacy versions.

    01010174
    2.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21717 A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a r… https://www.cve.org/CVERecord?id=CVE-2026-21717

    Post summary

    The post reports a newly identified vulnerability in V8 where integer-like strings produce predictable hash collisions, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00020207
    57.6K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Fedora 43 and 44 ship Node.js 20 with multiple DoS flaws CVE-2026-21717, CVE-2026-21714, CVE-2026-1525, CVE-2026-1526, fixed in urgent 20.20.2 update. https://threatcluster.io/cluster/critical-denial-of-service-vulnerabilities-in-nodejs-20-affe-ffaf0480

    Post summary

    The text announces the discovery of multiple DoS vulnerabilities in Node.js 20 shipped with Fedora 43 and 44, and notes that an urgent patch (20.20.2) has been released.

    0010050
    181 followersView on X
  • Aun shah/ Ali memon@Aunshah102
    Patch

    This release includes fixes for CVE-2026-21717, a critical array index hash collision, and CVE-2026-21713, which improves the security of Web Cryptography HMAC and KMAC operations through timing-safe comparisons. 2/6

    Post summary

    This release confirms that fixes for CVE-2026-21717 and CVE-2026-21713 are included, providing patch information and technical details about both vulnerabilities.

    1000043
    17 followersView on X
  • Aun shah/ Ali memon@Aunshah102
    Disclosure

    @rafaelgss Several medium severity issues were also resolved. CVE-2026-21717 addresses array index hash collisions, a common area for potential performance bottlenecks or denial-of-service vectors. 5/17

    Post summary

    The tweet announces that CVE‑2026‑21717, a medium‑severity issue involving array hash collisions, has been fixed, yet it offers no PoC, exploit code or evidence of active exploitation.

    1000026
    17 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-21717 A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a r… https://www.cve.org/CVERecord?id=CVE-2026-21717 ----- Traducción: CVE-2026-21717 Un … http://infoflow.cloud`

    Post summary

    This tweet announces CVE‑2026‑21717, explaining a V8 hashing flaw that leads to predictable collisions, but it contains no PoC, exploit, or patch discussion.

    0000024
    65 followersView on X
  • ティー🌐@TeeTheta
    Patch

    対処された脆弱性(22.x対象8件) CVE-2026-21637 (High) CVE-2026-21710 (High) CVE-2026-21713 (Medium) CVE-2026-21714 (Medium) CVE-2026-21717 (Medium) CVE-2026-21715 (Low) CVE-2026-21716 (Low) undici 6.24.1/7.24.4 への依存更新

    Post summary

    The post lists eight CVEs that are mitigated by upgrading the undici library to versions 6.24.1 or 7.24.4, providing a clear patch update.

    0000071
    1 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v24.14.1 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリースです。 • undiciを7.24.4に更新 • npmを11.11.0にアップグレード • V8の依存関係を更新 🔧 重要な修正: • (CVE-2026-21710) headersDistinct/trailersDistinctにnullプロトタイプを使用 • (CVE-2026-21637) SNICallback呼び出しをtry/catchでラップ • (CVE-2026-21717) 配列インデックスのハッシュ衝突をテスト • (CVE-2026-21713) Web Cryptography HMACおよびKMACでタイミング安全な比較を使用 • (CVE-2026-21714) NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 • (CVE-2026-21712) 異なるURL形式でのURLクラッシュを処理 • (CVE-2026-21716) lib/fs/promisesにパーミッションチェックを含める • (CVE-2026-21715) realpath.nativeにパーミッションチェックを追加 #GitHub #Release #Node.js

    Post summary

    The Node.js 24.14.1 release is a security patch that fixes several CVEs, providing brief technical details for each fix.

    0000066
    2 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v25.8.2 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリース。 🔧 重要な修正: • SNICallbackの呼び出しをtry/catchでラップ (CVE-2026-21637) - 高 • headersDistinct/trailersDistinctにnullプロトタイプを使用 (CVE-2026-21710) - 高 • pipe_wrap.ccにパーミッションチェックを追加 (CVE-2026-21711) - 中 • 異なるURL形式でのURLクラッシュを処理 (CVE-2026-21712) - 中 • Web Cryptography HMACおよびKMACでタイミングセーフな比較を使用 (CVE-2026-21713) - 中 • NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 (CVE-2026-21714) - 中 • 配列インデックスハッシュ衝突のテスト (CVE-2026-21717) - 中 • realpath.nativeにパーミッションチェックを追加 (CVE-2026-21715) - 低 • lib/fs/promisesにパーミッションチェックを追加 (CVE-2026-21716) - 低 #GitHub #Release #Node.js

    Post summary

    The announcement focuses on the Node.js 25.8.2 patch release which addresses multiple CVEs; no PoC, exploit, or active exploitation information is included.

    0000049
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js---

Explore more