CVE-2026-21710: High severity Node.js Node.js vulnerability

Published Mar 30, 2026
·
Updated

A flaw in Node.js HTTP request handling causes an uncaught TypeError when a request is received with a header named proto and the application accesses req.headersDistinct.

When this occurs, dest["proto"] resolves to Object.prototype rather than undefined, causing .push() to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by error event listeners, meaning it cannot be handled without wrapping every req.headersDistinct access in a try/catch.

This vulnerability affects all Node.js HTTP servers on 20.x, 22.x, 24.x, and v25.x

Affected Software

15 affected componentsFixes available
Node.js Node.js>=20.0.0<21.0.0, >=22.0.0<23.0.0, >=24.0.0<25.0.0, >=25.0.0<26.0.0
Microsoft azl3 nodejs 20.14.0-14
Microsoft azl3 nodejs24 24.13.0-3
Microsoft azl3 nodejs24 24.13.0-3<24.14.1-1
24.14.1-1
Microsoft azl3 nodejs 20.14.0-14<20.14.0-15
20.14.0-15
Nodejs Node.js<=20.20.1
Nodejs Node.js>=22.0.0<=22.22.1
Nodejs Node.js>=24.0.0<=24.14.0
Nodejs Node.js>=25.0.0<=25.8.1
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0
redhat Enterprise Linux Eus=9.4
redhat Enterprise Linux Eus=9.6
redhat Enterprise Linux Eus=10.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 24.14.1-1
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 20.14.0-15

Event History

Mar 30, 2026
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
DescriptionSeverity
Data Sourced
via Red Hat·08:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Apr 1, 2026
Data Sourced
via Microsoft·08:16 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:16 AM
Affected Software
Updated
via Microsoft·08:16 AM
DescriptionSeverityWeakness
Updated
via Microsoft·08:16 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2026-21710?

CVE-2026-21710 is classified as a medium severity vulnerability.

2

How do I fix CVE-2026-21710?

To fix CVE-2026-21710, upgrade Node.js to a version that is not affected, such as 21.0.0 or later.

3

Which versions of Node.js are affected by CVE-2026-21710?

CVE-2026-21710 affects Node.js versions from 20.0.0 up to 26.0.0, excluding the specified fixed versions.

4

What is the impact of CVE-2026-21710 on applications?

The impact of CVE-2026-21710 can lead to uncaught exceptions in applications that handle HTTP requests with specific headers.

5

Is CVE-2026-21710 a remote code execution vulnerability?

No, CVE-2026-21710 does not lead to remote code execution but may cause application crashes due to unhandled errors.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203