CVE-2026-21710
ADVISORY - nistSummary
A flaw in Node.js HTTP request handling causes an uncaught TypeError when a request is received with a header named __proto__ and the application accesses req.headersDistinct.
When this occurs, dest["__proto__"] resolves to Object.prototype rather than undefined, causing .push() to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by error event listeners, meaning it cannot be handled without wrapping every req.headersDistinct access in a try/catch.
- This vulnerability affects all Node.js HTTP servers on 20.x, 22.x, 24.x, and v25.x
Common Weakness Enumeration (CWE)
Access of Resource Using Incompatible Type ('Type Confusion')
Docker
BSA-2026-21710
-
Docker
CVE-2026-21710
-
NIST
CVSS SCORE
7.5highAlpine
-
Debian
-
CVSS SCORE
N/AlowUbuntu
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AhighAlma
-
CVSS SCORE
N/AhighAlma
-
CVSS SCORE
N/AhighAlma
-
CVSS SCORE
N/AhighAlma
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighBitnami
BIT-node-2026-21710
3.9
CVSS SCORE
7.5highBitnami
BIT-node-min-2026-21710
3.9
CVSS SCORE
7.5highRed Hat
3.9
CVSS SCORE
7.5highRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighChainguard
CGA-fmmf-9rjw-6f83
-
Photon
CVE-2026-21710
-
CVSS SCORE
7.5highminimos
MINI-32gw-w7gv-h9m9
-
minimos
MINI-492r-pc2g-2wg5
-
minimos
MINI-7q5j-jh2h-5hpm
-
minimos
MINI-97jq-gqf8-599q
-
minimos
MINI-cv89-6xw4-w943
-
minimos
MINI-pw39-qm2v-8425
-
minimos
MINI-r7vg-g62m-xr5g
-