CVE-2023-23919

HIGH

Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 - DoS

Title source: llm
STIX 2.1

Description

A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent cryptographic operations that happen to be on the same thread. This in turn could be used to cause a denial of service.

References (3)

Core 3

Scores

CVSS v3 7.5
EPSS 0.0032
EPSS Percentile 55.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-310
Status published
Products (2)
nodejs/node.js 14.0.0 - 14.14.0
nodejs/node.js 14.0.0 - 14.21.3
Published Feb 23, 2023
Tracked Since Feb 18, 2026