{"id":"CVE-2026-21717","title":"A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable","summary":"A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, …","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-328"],"vendor":"nodejs","product":"node.js","affected":["node.js <= 20.20.1","node.js >= 22.0.0, <= 22.22.1","node.js >= 24.0.0, <= 24.14.0","node.js >= 25.0.0, <= 25.8.1"],"published":"2026-03-30","updated":"2026-08-19","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-21717","references":[{"url":"https://nodejs.org/en/blog/vulnerability/march-2026-security-releases","label":"support@hackerone.com"}],"tags":["nvd","exploit-available"],"epss":0.00268,"epssPercentile":0.1915,"ingestedAt":"2026-08-19T13:39:32.947Z","exploits":{"github":1,"githubRepos":["https://github.com/open-flaw/CVE-2026-21717"],"checkedAt":"2026-09-21T15:28:28.068Z"},"exploitAvailable":true,"slug":"CVE-2026-21717","body":"## Overview\n\nA flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process.\r\n\r\nThe most common trigger is any endpoint that calls `JSON.parse()` on attacker-controlled input, as JSON parsing automatically internalizes short strings into the affected hash table.\r\n\r\nThis vulnerability affects **20.x, 22.x, 24.x, and 25.x**.\n\n## Affected\n\n- `node.js <= 20.20.1`\n- `node.js >= 22.0.0, <= 22.22.1`\n- `node.js >= 24.0.0, <= 24.14.0`\n- `node.js >= 25.0.0, <= 25.8.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5008,"id":"CVE-2026-21717","ts":1788887227931,"field":"exploit_available","old":"false","new":"true"},{"seq":3891,"id":"CVE-2026-21717","ts":1788886358859,"field":"exploit_available","old":"true","new":"false"},{"seq":2713,"id":"CVE-2026-21717","ts":1788883024562,"field":"exploit_available","old":"false","new":"true"},{"seq":1742,"id":"CVE-2026-21717","ts":1788882428568,"field":"exploit_available","old":"true","new":"false"},{"seq":848,"id":"CVE-2026-21717","ts":1788881861850,"field":"exploit_available","old":"false","new":"true"}]}