Junglewise Threat Intelligence

CVE-2026-21713: A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing

CVE-2026-21713 · Severity: medium · CVSS 5.9 · Published 2026-03-30

Executive brief

A security flaw in Node.js affects how the system verifies digital signatures (HMACs) used to ensure data authenticity. Because the verification process takes a slightly different amount of time depending on how much of the signature is correct, an attacker could potentially guess valid signatures by measuring these tiny timing differences. If successful, this could allow an attacker to forge signatures, potentially bypassing security checks or gaining unauthorized access to protected data.

Technical details

A timing side-channel vulnerability exists in Node.js HMAC verification due to the use of non-constant-time memory comparison (memcmp) in crypto_hmac.cc. When validating user-provided signatures, the comparison returns early upon finding a mismatch, leaking timing information proportional to the number of matching leading bytes. In environments where high-resolution timing measurements are possible, a remote attacker can exploit this as a timing oracle to iteratively guess and forge valid HMAC values. The issue affects Node.js versions 20.x, 22.x, 24.x, and 25.x, and has been addressed in security releases v20.20.2, v22.22.2, v24.14.1, and v25.8.2.

Affected products

  • Node.js Node.js 20.x, 22.x, 24.x, 25.x

Timeline

  • 2026-03-24: patched: Security releases v20.20.2, v22.22.2, v24.14.1, and v25.8.2 published.
  • 2026-03-30: disclosed: NVD publication date.

References