VDB
GCVE-VVD-MAGEIA-2026-71
GCVE-VVD-MAGEIA-2026-71
Advisory Published
Incomplete fix for CVE-2026-21637: loadSNI() in _tls_wrap.js lacks
try/catch leading to Remote DoS. (CVE-2026-21637)
Denial of Service via __proto__ header name in req.headersDistinct
(Uncaught TypeError crashes Node.js process). (CVE-2026-21710)
Timing side-channel in HMAC verification via memcmp() in crypto_hmac.cc
leads to potential MAC forgery. (CVE-2026-21713)
Memory leak in Node.js HTTP/2 server via WINDOW_UPDATE on stream 0 leads
to resource exhaustion. (CVE-2026-21714)
Permission Model Bypass in realpathSync.native Allows File Existence
Disclosure. (CVE-2026-21715)
CVE-2024-36137 Patch Bypass - FileHandle.chmod/chown. (CVE-2026-21716)
HashDoS in V8. (CVE-2026-21717)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | nodejs | 0 (affected), 22.22.2-1.mga9 (unaffected) | — |
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.