CVE-2026-21712 - CERT CVE
ID CVE-2026-21712
Sažetak A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
Reference
CVSS
Base: 5.7
Impact: 3.6
Exploitability:2.1
Pristup
VektorSloženostAutentikacija
NETWORK LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
NONE NONE HIGH
CVSS vektor CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Zadnje važnije ažuriranje 30-03-2026 - 16:16
Objavljeno 30-03-2026 - 16:16