CVE-2021-22883: vulnerability in NodeJS Node
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Node.js can crash or become unresponsive when an attacker sends many connection attempts using an unknown protocol, causing the server to run out of file descriptors or memory. This prevents legitimate users from connecting and may affect the entire system.
A denial of service vulnerability in Node.js allows an unauthenticated attacker to exhaust file descriptor resources by establishing multiple connections with an 'unknownProtocol' value, resulting in descriptor leaks. When file descriptor limits are enforced, new connections are rejected and file operations fail; without limits, excessive memory consumption leads to system-wide resource exhaustion.
In the same product, most dangerous first.