CVE-2026-21710

Name
CVE-2026-21710
Description
A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
support@hackerone.com https://nodejs.org/en/blog/vulnerability/march-2026-security-releases
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:7080
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:7123
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:7302
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:7310
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:7350
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:7670
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:7675
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:7896
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:7983
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:8339
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:9711
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/errata/RHSA-2026:9874
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/security/cve/CVE-2026-21710
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://bugzilla.redhat.com/show_bug.cgi?id=2453151
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21710.json

Match rules

CPE URI Source package Min version Max version

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nodejs edge-main 24.14.1-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
nodejs 3.23-main 24.14.1-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
nodejs 3.22-main 22.22.2-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
nodejs 3.21-main 22.22.2-r0 Jakub Jirutka <jakub@jirutka.cz> fixed