Home
MEDIUM: 5.7 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:HDefault status
unaffected
24.14.0 (semver)
affected
25.8.1 (semver)
affected
Description
A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
Product status
24.14.0 (semver)
25.8.1 (semver)
References
nodejs.org/...log/vulnerability/march-2026-security-releases