← Back

CVE-2026-21637

nvd nist
Published: Jan 20, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

Affected (4)

Products: Nodejs: Node.js
1 product
Node.js
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
From 22.0.0 to 22.22.0
From 24.0.0 to 24.13.0
From 25.0.0 to 25.3.0
From 4.0.0 to 20.20.0

References (1)

Source: support@hackerone.com
Release NotesVendor Advisory

Timeline

No history available yet.