CVE-2026-21712

Published: March 26, 2026Last modified: March 28, 2026

Description

A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.

Severity score breakdown

ParameterValue
Base score5.7
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredLOW
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSnodejsNot affected (18.16.0-r0)
25 LTSnodejsNot affected (22.16.0-r1)
StreamnodejsFixed (24.14.1-r0)
Hardened Containers23 LTSnodejsNot affected (18.16.0-r0)
25 LTSnodejsNot affected (22.16.0-r1)
StreamnodejsFixed (24.14.1-r0)

References

ON THIS PAGE