CVE-2026-21713 — A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. U — CVE Database · The Intelligence Room