7.5

CVE-2026-21710

Medienbericht
A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`.

When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`.

* This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NodejsNode.Js SwEdition- Version <= 20.20.1
NodejsNode.Js SwEdition- Version >= 22.0.0 <= 22.22.1
NodejsNode.Js SwEdition- Version >= 24.0.0 <= 24.14.0
NodejsNode.Js SwEdition- Version >= 25.0.0 <= 25.8.1
RedhatEnterprise Linux Version8.0
RedhatEnterprise Linux Version9.0
RedhatEnterprise Linux Version10.0
RedhatEnterprise Linux Eus Version9.4
RedhatEnterprise Linux Eus Version9.6
RedhatEnterprise Linux Eus Version10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 25.04% 0.977
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
HackerOne 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
01.04.2026 09:30
https://nodejs.org/en/blog/vulnerability/march-2026-security-releases
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2453151
Issue Tracking
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21710.json
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:7080
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:7123
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:7302
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:7310
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:7350
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:7670
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:7675
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:7896
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:7983
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:8339
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:9711
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:9874
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2026-21710
Third Party Advisory