REDHAT-BUG-2453037: Medium severity OpenJS Foundation Node.js vulnerability
Published Mar 30, 2026
·Updated
A flaw in Node.js URL processing causes an assertion failure in native code when url.format() is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
Affected Software
1 affected component
OpenJS Foundation Node.js
Event History
Mar 30, 2026
Data Sourced
via Red Hat·04:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2453037?
The severity of REDHAT-BUG-2453037 is medium, rated at 4.
2
What causes the vulnerability identified by REDHAT-BUG-2453037?
REDHAT-BUG-2453037 is caused by a flaw in Node.js URL processing that leads to an assertion failure with malformed internationalized domain names.
3
How does REDHAT-BUG-2453037 affect Node.js applications?
REDHAT-BUG-2453037 can cause a crash in the Node.js process when `url.format()` is called with an invalid IDN.
4
How do I fix REDHAT-BUG-2453037?
To fix REDHAT-BUG-2453037, update your Node.js version to incorporate the latest security patches.
5
Which software is affected by REDHAT-BUG-2453037?
REDHAT-BUG-2453037 affects OpenJS Foundation Node.js.