{"id":"CVE-2026-21710","title":"A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`.\r\n\r\nWhen this occurs, `dest[\"__proto__\"]` resolves to `O…","summary":"A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`.\r\n\r\nWhen this occurs, `dest[\"__proto__\"]` resolves to `O…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-770","CWE-843"],"vendor":"nodejs","product":"node.js","affected":["node.js <= 20.20.1","node.js >= 22.0.0, <= 22.22.1","node.js >= 24.0.0, <= 24.14.0","node.js >= 25.0.0, <= 25.8.1","enterprise_linux = 8.0","enterprise_linux = 9.0","enterprise_linux = 10.0","enterprise_linux_eus = 9.4","enterprise_linux_eus = 9.6","enterprise_linux_eus = 10.0"],"published":"2026-03-30","updated":"2026-08-19","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-21710","references":[{"url":"https://nodejs.org/en/blog/vulnerability/march-2026-security-releases","label":"support@hackerone.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:7080","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:7123","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:7302","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:7310","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:7350","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:7670","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:7675","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:7896","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:7983","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:8339","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:9711","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:9874","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-21710","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2453151","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21710.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"tags":["nvd","exploit-available"],"epss":0.25044,"epssPercentile":0.97823,"ingestedAt":"2026-08-19T14:40:19.126Z","exploits":{"github":1,"githubRepos":["https://github.com/open-flaw/CVE-2026-21710"],"checkedAt":"2026-09-23T07:13:54.614Z"},"exploitAvailable":true,"slug":"CVE-2026-21710","body":"## Overview\n\nA flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`.\r\n\r\nWhen this occurs, `dest[\"__proto__\"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`.\r\n\r\n* This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**\n\n## Affected\n\n- `node.js <= 20.20.1`\n- `node.js >= 22.0.0, <= 22.22.1`\n- `node.js >= 24.0.0, <= 24.14.0`\n- `node.js >= 25.0.0, <= 25.8.1`\n- `enterprise_linux = 8.0`\n- `enterprise_linux = 9.0`\n- `enterprise_linux = 10.0`\n- `enterprise_linux_eus = 9.4`\n- `enterprise_linux_eus = 9.6`\n- `enterprise_linux_eus = 10.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":58,"depthScoreParts":{"impact":41.3,"likelihood":5,"exploitation":12,"ransomware":0},"changes":[{"seq":5007,"id":"CVE-2026-21710","ts":1788887227892,"field":"exploit_available","old":"false","new":"true"},{"seq":3890,"id":"CVE-2026-21710","ts":1788886358819,"field":"exploit_available","old":"true","new":"false"},{"seq":2712,"id":"CVE-2026-21710","ts":1788883024522,"field":"exploit_available","old":"false","new":"true"},{"seq":1741,"id":"CVE-2026-21710","ts":1788882428533,"field":"exploit_available","old":"true","new":"false"},{"seq":847,"id":"CVE-2026-21710","ts":1788881861812,"field":"exploit_available","old":"false","new":"true"}]}