Bug 2453603 - CVE-2026-21712 nodejs20: Node.js: Denial of Service via malformed Internationalized Domain Name processing [fedora-all]
Summary: CVE-2026-21712 nodejs20: Node.js: Denial of Service via malformed Internation...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: nodejs20
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Jan Staněk
QA Contact:
URL:
Whiteboard: {"flaws": ["071cfad5-5fcf-4930-a738-b...
Depends On:
Blocks: CVE-2026-21712
TreeView+ depends on / blocked
 
Reported: 2026-03-31 22:27 UTC by Jon Moroney
Modified: 2026-04-22 15:16 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-04-22 15:16:41 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Jon Moroney 2026-03-31 22:27:03 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 TomasJuhasz 2026-04-22 15:16:41 UTC
This vulnerability has been reported only against nodejs24 and nodejs25 and should not be present in nodejs20.

From upstream report:
Assertion error in node_url.cc via malformed URL format leads to Node.js crash (CVE-2026-21712) - (Medium)

A flaw in Node.js URL processing causes an assertion failure in native code when url.format() is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.

    This vulnerability affects 24.x and 25.x.


Note You need to log in before you can comment on or make changes to this bug.