Description
A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`.

When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`.

* This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**
Published: 2026-03-30
Score: 7.5 High
EPSS: 26.4% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Node.js HTTP request handling triggers an uncaught TypeError when a request contains a header named __proto__ and the application accesses req.headersDistinct. The fault occurs because accessing dest["__proto__"] resolves to Object.prototype, causing a .push() call on a non-array and resulting in a synchronous exception that cannot be caught by standard error handlers. This manifests as a crash of the Node.js process, leading to a denial of service. The weakness is a type confusion error (CWE‑843) that results in resource exhaustion (CWE‑770) through repeated crashes.

Affected Systems

All Node.js HTTP servers built on the Node.js runtime in the 20.x, 22.x, 24.x, and v25.x branches are affected. Any application that relies on the default HTTP module and accesses request headers via req.headersDistinct is susceptible to this crash when receiving the crafted header.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as moderately high severity, while the EPSS score of 0.26% indicates a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the crash simply by sending a crafted HTTP request containing the __proto__ header from any network location that can reach the vulnerable server, leading to an immediate denial of service. The exception is thrown synchronously inside a property getter and cannot be mitigated by generic error handling, underscoring the need for a specific patch or temporary workaround.

Generated by OpenCVE AI on June 30, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all affected Node.js installations to the latest repair release that incorporates the March 2026 security fix (including the 20.x, 22.x, 24.x, or v25.x branches).
  • If an upgrade is not yet possible, surround every access to req.headersDistinct with a try/catch block so that the exception is caught and handled gracefully.
  • Validate incoming request headers to reject or strip any __proto__ header before it reaches application code, preventing the malicious header from triggering the bug.

Generated by OpenCVE AI on June 30, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6183-1 nodejs security update
Debian DSA Debian DSA DSA-6272-1 nodejs security update
History

Wed, 01 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unhandled TypeError from __proto__ Header in Node.js HTTP Request Handling Node.js: Node.js: Denial of Service due to crafted HTTP `__proto__` header
First Time appeared Nodejs
Nodejs nodejs
Weaknesses CWE-20 CWE-843
Vendors & Products Nodejs
Nodejs nodejs
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Tue, 31 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 31 Mar 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unhandled TypeError from __proto__ Header in Node.js HTTP Request Handling
Weaknesses CWE-20

Mon, 30 Mar 2026 19:30:00 +0000

Type Values Removed Values Added
Description A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-07-15T01:19:57.306Z

Reserved: 2026-01-04T15:00:06.574Z

Link: CVE-2026-21710

cve-icon Vulnrichment

Updated: 2026-06-30T02:43:18.595Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-30T20:16:18.210

Modified: 2026-06-17T10:18:57.163

Link: CVE-2026-21710

cve-icon Redhat

Severity : Important

Publid Date: 2026-03-30T19:07:28Z

Links: CVE-2026-21710 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T16:30:16Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling

  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')