← back
CVE-2019-15604CWE-295

CVE-2019-15604

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 20%
exploitation probability
20%top 3% of all CVEs
observed exploitation
nono source reports it
In short

Node.js versions 10, 12, and 13 do not properly validate X.509 certificates, allowing an attacker to send a specially crafted certificate that crashes the application.

Technical detail

CWE-295 vulnerability in Node.js certificate validation logic allows an unauthenticated remote attacker to trigger a process abort by sending a malformed X.509 certificate, resulting in denial of service through improper validation of certificate structure or integrity.

Summary generated and translated by AI from the official description.
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
Affected products
NodeJS · Node