CVE-2026-21716 | Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1 Promises API FileHandle.chmod/FileHandle.chown file descriptor consumption (EUVD-2026-17180 / Nessus ID 304242)
A vulnerability labeled as problematic has been found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1. This vulnerability affects the function FileHandle.chmod/FileHandle.chown of the component Promises API. Executing a manipulation can lead to uncontrolled file descriptor consumption.
This vulnerability is registered as CVE-2026-21716. The attack needs to be launched locally. No exploit is available.
Applying a patch is advised to resolve this issue.