Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
This issue was only raised against nodejs24/25 explicitly. From upstream security release blog: Assertion error in node_url.cc via malformed URL format leads to Node.js crash (CVE-2026-21712) - (Medium) A flaw in Node.js URL processing causes an assertion failure in native code when url.format() is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process. **This vulnerability affects 24.x and 25.x.**