CVE-2026-21712

A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
Configurations

No configuration.

History

10 May 2026, 14:16

Type Values Removed Values Added
CWE CWE-20

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) Una falla en el procesamiento de URL de Node.js causa una falla de aserción en código nativo cuando se llama a 'url.format()' con un nombre de dominio internacionalizado (IDN) malformado que contiene caracteres no válidos, colapsando el proceso de Node.js.

30 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 16:16

Updated : 2026-05-10 14:16


NVD link : CVE-2026-21712

Mitre link : CVE-2026-21712

CVE.ORG link : CVE-2026-21712


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation