THREAT OPS › Threat News › [NVD] CVE-2026-21717 (MEDIUM 5.9) — A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade perfo
[NVD] CVE-2026-21717 (MEDIUM 5.9) — A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade perfo
CVE-2026-21717 CVSS: 5.9 MEDIUM Published: 2026-03-30T20:16:20.010
A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process.
The most common tr
Indicators of compromise
- CVE-2026-21717cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-21717