Описание
A flaw in Node.js WebCrypto implementation can crash the process if the input of subtle.encrypt() is a multiple of 2GiB.
This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the subtle.encrypt() function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.
Отчет
This is an Important denial of service vulnerability in Node.js WebCrypto, as a remote attacker can crash the Node.js process by providing a specially crafted large input to the subtle.encrypt() function. This could lead to service unavailability in Red Hat environments where Node.js applications process untrusted data with WebCrypto.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | nodejs22 | Affected | ||
| Red Hat Enterprise Linux 10 | nodejs24 | Affected | ||
| Red Hat Enterprise Linux 8 | nodejs:22/nodejs | Affected | ||
| Red Hat Enterprise Linux 8 | nodejs:24/nodejs | Affected | ||
| Red Hat Enterprise Linux 9 | nodejs:22/nodejs | Affected | ||
| Red Hat Enterprise Linux 9 | nodejs:24/nodejs | Affected | ||
| Red Hat Hardened Images | nodejs22-main-22.23.1-1.hum1 | Fixed | RHSA-2026:28727 | 24.06.2026 |
| Red Hat Hardened Images | nodejs24-main-24.18.0-0.1.hum1 | Fixed | RHSA-2026:29012 | 24.06.2026 |
| Red Hat Hardened Images | nodejs26-main-26.4.0-1.2.hum1 | Fixed | RHSA-2026:30172 | 25.06.2026 |
| Red Hat Hardened Images | nodejs25-main-25.9.0-1.1.hum1 | Fixed | RHSA-2026:7378 | 10.04.2026 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
A flaw in Node.js WebCrypto implementation can crash the process if th ...
A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
7.5 High
CVSS3