CVE-2026-21710
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
Security Fix(es):
- minimatch: minimatch: Denial of Service via specially crafted glob patterns (CVE-2026-26996)
- minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions (CVE-2026-27904)
- nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135)
- Node.js: Node.js: Denial of Service due to crafted HTTP
protoheader (CVE-2026-21710)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/errata/RHSA-2026:7896, https://access.redhat.com/security/cve/CVE-2026-21710, https://access.redhat.com/security/cve/CVE-2026-26996, https://access.redhat.com/security/cve/CVE-2026-27135, https://access.redhat.com/security/cve/CVE-2026-27904
