Логотип exploitDog
bind:"CVE-2026-21637"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2026-21637"

Количество 27

Количество 27

ubuntu логотип

CVE-2026-21637

2 месяца назад

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-21637

2 месяца назад

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-21637

2 месяца назад

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-21637

2 месяца назад

A flaw in Node.js TLS error handling allows remote attackers to crash ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-ggxc-26fx-987r

2 месяца назад

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 5.9
EPSS: Низкий
fstec логотип

BDU:2026-00548

2 месяца назад

Уязвимость функций pskCallback() и ALPNCallback() программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:2783

около 1 месяца назад

Important: nodejs:20 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2782

около 1 месяца назад

Important: nodejs:22 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2781

около 1 месяца назад

Important: nodejs:24 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2422

около 1 месяца назад

Important: nodejs:20 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2421

около 1 месяца назад

Important: nodejs:22 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2420

около 1 месяца назад

Important: nodejs:24 security update

EPSS: Низкий
rocky логотип

RLSA-2026:1843

около 2 месяцев назад

Important: nodejs22 security update

EPSS: Низкий
rocky логотип

RLSA-2026:1842

около 2 месяцев назад

Important: nodejs24 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2783

около 1 месяца назад

ELSA-2026-2783: nodejs:20 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2782

около 1 месяца назад

ELSA-2026-2782: nodejs:22 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2781

около 1 месяца назад

ELSA-2026-2781: nodejs:24 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2422

около 1 месяца назад

ELSA-2026-2422: nodejs:20 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2421

около 1 месяца назад

ELSA-2026-2421: nodejs:22 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2420

около 1 месяца назад

ELSA-2026-2420: nodejs:24 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-21637

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 7.5
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-21637

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 5.9
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-21637

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 7.5
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-21637

A flaw in Node.js TLS error handling allows remote attackers to crash ...

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-ggxc-26fx-987r

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 5.9
0%
Низкий
2 месяца назад
fstec логотип
BDU:2026-00548

Уязвимость функций pskCallback() и ALPNCallback() программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:2783

Important: nodejs:20 security update

около 1 месяца назад
rocky логотип
RLSA-2026:2782

Important: nodejs:22 security update

около 1 месяца назад
rocky логотип
RLSA-2026:2781

Important: nodejs:24 security update

около 1 месяца назад
rocky логотип
RLSA-2026:2422

Important: nodejs:20 security update

около 1 месяца назад
rocky логотип
RLSA-2026:2421

Important: nodejs:22 security update

около 1 месяца назад
rocky логотип
RLSA-2026:2420

Important: nodejs:24 security update

около 1 месяца назад
rocky логотип
RLSA-2026:1843

Important: nodejs22 security update

около 2 месяцев назад
rocky логотип
RLSA-2026:1842

Important: nodejs24 security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-2783

ELSA-2026-2783: nodejs:20 security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-2782

ELSA-2026-2782: nodejs:22 security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-2781

ELSA-2026-2781: nodejs:24 security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-2422

ELSA-2026-2422: nodejs:20 security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-2421

ELSA-2026-2421: nodejs:22 security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-2420

ELSA-2026-2420: nodejs:24 security update (IMPORTANT)

около 1 месяца назад

Уязвимостей на страницу