CVE-2026-21637

Severity
7.5HIGH
EPSS
0.0%
top 86.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 20

Description

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client ca

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5nodejs/node4.04.*+18
NVDnodejs/node.js4.0.020.20.0+3
Debiannodejs< 20.19.2+dfsg-1+deb13u2+1

🔴Vulnerability Details

3
GHSA
GHSA-ggxc-26fx-987r: A flaw in Node2026-01-20
CVEList
CVE-2026-21637: A flaw in Node2026-01-20
OSV
CVE-2026-21637: A flaw in Node2026-01-20

📋Vendor Advisories

2
Red Hat
nodejs: Nodejs denial of service2026-01-20
Debian
CVE-2026-21637: nodejs - A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-21637 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2026-21637 nodejs: Nodejs denial of service2026-01-20
CVE-2026-21637 (HIGH CVSS 7.5) | A flaw in Node.js TLS error handlin | cvebase.io