CVE-2026-21712
published 2026-03-30CVE-2026-21712: A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN)…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.32%
24.7th percentile
A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | — | — |
| nodejs | node | 24.14.0 – 24.14.0 | — |
| nodejs | node | 25.8.1 – 25.8.1 | — |
| nodejs | node.js | 24.0.0 – 24.14.0 | — |
| nodejs | node.js | 25.0.0 – 25.8.1 | — |
| nodejs | nodejs | >= 0 < 24.14.1-r0 | 24.14.1-r0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv3.05.7MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
osv5.7MEDIUM
vendor_debian5.7LOW
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Node.js: Node.js: Denial of Service via malformed Internationalized Domain Name processing
vendor_redhat·2026-03-30·CVSS 5.7
CVE-2026-21712 [MEDIUM] CWE-168 Node.js: Node.js: Denial of Service via malformed Internationalized Domain Name processing
Node.js: Node.js: Denial of Service via malformed Internationalized Domain Name processing
A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
A flaw was found in Node.js. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a malformed Internationalized Domain Name (IDN) to the `url.format()` function. When processed, this malformed input triggers an internal error, causing the Node.js application to crash. This can disrupt services and make them unavailable.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Se
Debian
CVE-2026-21712: nodejs - A flaw in Node.js URL processing causes an assertion failure in native code when...
vendor_debian·2026·CVSS 5.7
CVE-2026-21712 [MEDIUM] CVE-2026-21712: nodejs - A flaw in Node.js URL processing causes an assertion failure in native code when...
A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-h8r7-m85c-mjhv: A flaw in Node
ghsa_unreviewed·2026-03-30
CVE-2026-21712 [MEDIUM] GHSA-h8r7-m85c-mjhv: A flaw in Node
A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
OSV
CVE-2026-21712: A flaw in Node
osv·2026-03-30·CVSS 5.7
CVE-2026-21712 [MEDIUM] CVE-2026-21712: A flaw in Node
A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-21712 nodejs22: Node.js: Denial of Service via malformed Internationalized Domain Name processing [fedora-all]
bugzilla·2026-03-31·CVSS 5.7
CVE-2026-21712 [MEDIUM] CVE-2026-21712 nodejs22: Node.js: Denial of Service via malformed Internationalized Domain Name processing [fedora-all]
CVE-2026-21712 nodejs22: Node.js: Denial of Service via malformed Internationalized Domain Name processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This issue was only raised against nodejs24/25 explicitly.
From upstream security release blog:
Assertion error in node_url.cc via malformed URL format leads to Node.js crash (CVE-2026-21712) - (Medium)
A flaw in Node.js URL processing causes an assertion failure in native code when url.format() is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
**This vulnerabil
Bugzilla
CVE-2026-21712 nodejs18: Node.js: Denial of Service via malformed Internationalized Domain Name processing [fedora-all]
bugzilla·2026-03-31·CVSS 5.7
CVE-2026-21712 [MEDIUM] CVE-2026-21712 nodejs18: Node.js: Denial of Service via malformed Internationalized Domain Name processing [fedora-all]
CVE-2026-21712 nodejs18: Node.js: Denial of Service via malformed Internationalized Domain Name processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
Bugzilla
CVE-2026-21712 nodejs20: Node.js: Denial of Service via malformed Internationalized Domain Name processing [fedora-all]
bugzilla·2026-03-31·CVSS 5.7
CVE-2026-21712 [MEDIUM] CVE-2026-21712 nodejs20: Node.js: Denial of Service via malformed Internationalized Domain Name processing [fedora-all]
CVE-2026-21712 nodejs20: Node.js: Denial of Service via malformed Internationalized Domain Name processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This vulnerability has been reported only against nodejs24 and nodejs25 and should not be present in nodejs20.
From upstream report:
Assertion error in node_url.cc via malformed URL format leads to Node.js crash (CVE-2026-21712) - (Medium)
A flaw in Node.js URL processing causes an assertion failure in native code when url.format() is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing th
Bugzilla
CVE-2026-21712 Node.js: Node.js: Denial of Service via malformed Internationalized Domain Name processing
bugzilla·2026-03-30·CVSS 5.7
CVE-2026-21712 [MEDIUM] CVE-2026-21712 Node.js: Node.js: Denial of Service via malformed Internationalized Domain Name processing
CVE-2026-21712 Node.js: Node.js: Denial of Service via malformed Internationalized Domain Name processing
A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:7350 https://access.redhat.com/errata/RHSA-2026:7350
Wiz
CVE-2026-21712 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.7
CVE-2026-21712 [MEDIUM] CVE-2026-21712 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21712 :
Node.js vulnerability analysis and mitigation
url.format()
Source : NVD
## 5.7
Score
Published March 30, 2026
Severity MEDIUM
CNA Score 5.7
Affected Technologies
Node.js
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
nodejs-npm
nodejs:20::nodejs-devel
Sources
NVD
Alpine 3.23, edge Severity MEDIUM Has Fix Added at: Mar 26, 2026
Debian 11, 12, 13, 14 No Fix Added at: Mar 25, 2026
Echo No Fix Added at: Mar 25, 2026
MinimOS Severity MEDIUM Has Fix Added at: Apr 02, 2026
Red Hat 8, 9, 10 Severity MEDIUM No Fix Added at: Apr 02, 2026
Linux Severity MEDIUM Has Fix Added at:
2026-03-30
Published