Security Advisory

CVE-2026-21712

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-30 15:13:59
Last updated 2026-05-10 13:16:37
Assigner hackerone
State PUBLISHED

Description

A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.