Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 42

Количество 42

ubuntu логотип

CVE-2026-21637

6 месяцев назад

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-21637

6 месяцев назад

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-21637

6 месяцев назад

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-21637

4 месяца назад

HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-21637

6 месяцев назад

A flaw in Node.js TLS error handling allows remote attackers to crash ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-ggxc-26fx-987r

6 месяцев назад

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 5.9
EPSS: Низкий
fstec логотип

BDU:2026-00548

7 месяцев назад

Уязвимость функций pskCallback() и ALPNCallback() программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260417-73-0033

4 месяца назад

Уязвимость nodejs

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:2783

5 месяцев назад

Important: nodejs:20 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2782

5 месяцев назад

Important: nodejs:22 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2781

5 месяцев назад

Important: nodejs:24 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2422

6 месяцев назад

Important: nodejs:20 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2421

6 месяцев назад

Important: nodejs:22 security update

EPSS: Низкий
rocky логотип

RLSA-2026:2420

6 месяцев назад

Important: nodejs:24 security update

EPSS: Низкий
rocky логотип

RLSA-2026:1843

6 месяцев назад

Important: nodejs22 security update

EPSS: Низкий
rocky логотип

RLSA-2026:1842

6 месяцев назад

Important: nodejs24 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2783

5 месяцев назад

ELSA-2026-2783: nodejs:20 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2782

5 месяцев назад

ELSA-2026-2782: nodejs:22 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2781

5 месяцев назад

ELSA-2026-2781: nodejs:24 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2422

6 месяцев назад

ELSA-2026-2422: nodejs:20 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-21637

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-21637

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 5.9
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-21637

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
msrc логотип
CVE-2026-21637

HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers

CVSS3: 7.5
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-21637

A flaw in Node.js TLS error handling allows remote attackers to crash ...

CVSS3: 7.5
1%
Низкий
6 месяцев назад
github логотип
GHSA-ggxc-26fx-987r

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.

CVSS3: 5.9
1%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-00548

Уязвимость функций pskCallback() и ALPNCallback() программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
7 месяцев назад
redos логотип
ROS-20260417-73-0033

Уязвимость nodejs

CVSS3: 7.5
1%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:2783

Important: nodejs:20 security update

5 месяцев назад
rocky логотип
RLSA-2026:2782

Important: nodejs:22 security update

5 месяцев назад
rocky логотип
RLSA-2026:2781

Important: nodejs:24 security update

5 месяцев назад
rocky логотип
RLSA-2026:2422

Important: nodejs:20 security update

6 месяцев назад
rocky логотип
RLSA-2026:2421

Important: nodejs:22 security update

6 месяцев назад
rocky логотип
RLSA-2026:2420

Important: nodejs:24 security update

6 месяцев назад
rocky логотип
RLSA-2026:1843

Important: nodejs22 security update

6 месяцев назад
rocky логотип
RLSA-2026:1842

Important: nodejs24 security update

6 месяцев назад
oracle-oval логотип
ELSA-2026-2783

ELSA-2026-2783: nodejs:20 security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-2782

ELSA-2026-2782: nodejs:22 security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-2781

ELSA-2026-2781: nodejs:24 security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-2422

ELSA-2026-2422: nodejs:20 security update (IMPORTANT)

6 месяцев назад

Уязвимостей на страницу