CVE-2021-22883CWE-400

CVE-2021-22883: vulnerability in NodeJS Node

Published · Updated

25Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 77%
exploitation probability
77%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
1 product
Red Hat Quay 3
no_fix_planned: Will not fix
Fixed
7 products (354 components)
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Enterprise Linux AppStream EUS (v. 8.1) · Red Hat Enterprise Linux AppStream EUS (v. 8.2) · Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) · Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) · and others 2
Not affected
1 product (6 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 9
In short

Node.js can crash or become unresponsive when an attacker sends many connection attempts using an unknown protocol, causing the server to run out of file descriptors or memory. This prevents legitimate users from connecting and may affect the entire system.

Technical detail

A denial of service vulnerability in Node.js allows an unauthenticated attacker to exhaust file descriptor resources by establishing multiple connections with an 'unknownProtocol' value, resulting in descriptor leaks. When file descriptor limits are enforced, new connections are rejected and file operations fail; without limits, excessive memory consumption leads to system-wide resource exhaustion.

Summary generated and translated by AI from the official description.
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
Affected products
NodeJS · Node