Bug 2453604 - CVE-2026-21712 nodejs22: Node.js: Denial of Service via malformed Internationalized Domain Name processing [fedora-all]
Summary: CVE-2026-21712 nodejs22: Node.js: Denial of Service via malformed Internation...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: nodejs22
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Jan Staněk
QA Contact:
URL:
Whiteboard: {"flaws": ["071cfad5-5fcf-4930-a738-b...
Depends On:
Blocks: CVE-2026-21712
TreeView+ depends on / blocked
 
Reported: 2026-03-31 22:27 UTC by Jon Moroney
Modified: 2026-04-30 11:21 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-04-30 11:21:04 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Jon Moroney 2026-03-31 22:27:08 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 TomasJuhasz 2026-04-30 11:21:04 UTC
This issue was only raised against nodejs24/25 explicitly.

From upstream security release blog: 
Assertion error in node_url.cc via malformed URL format leads to Node.js crash (CVE-2026-21712) - (Medium)

A flaw in Node.js URL processing causes an assertion failure in native code when url.format() is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.

**This vulnerability affects 24.x and 25.x.**


Note You need to log in before you can comment on or make changes to this bug.