Vulnerability record · CVE-2021-22883 · published 3 March 2021
CVE-2021-22883: Node.js unknownProtocol connection flood leaks file descriptors
Nodejs · Node.Js
Node.js before 10.24.0, 12.21.0, 14.16.0 and 15.10.0 leaks file descriptors when many connection attempts using an 'unknownProtocol' are established. Repeated attempts exhaust the file descriptor limit or, where no limit is set, drive excessive memory use until the process or host runs out of resources. It matters because a remote unauthenticated client can take a Node.js service offline.
Description
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote unauthenticated denial of service with a CVSS of 7.5 and very high EPSS, though no KEV listing or known exploit code.
What it is
Node.js before 10.24.0, 12.21.0, 14.16.0 and 15.10.0 leaks file descriptors when many connection attempts using an 'unknownProtocol' are established. Repeated attempts exhaust the file descriptor limit or, where no limit is set, drive excessive memory use until the process or host runs out of resources. It matters because a remote unauthenticated client can take a Node.js service offline.
Impact
An attacker can exhaust file descriptors or memory on the Node.js process, causing it to stop accepting new connections and to fail opening files, resulting in denial of service.
Attack surface
Reachable over the network against a listening Node.js service; the CVSS vector shows no privileges and no user interaction required. The flaw triggers on connection attempts that negotiate an unknown protocol, so any exposed TLS or protocol-negotiating endpoint is a candidate.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.74352, 99.467th percentile), indicating elevated likelihood of attempted exploitation. References include patch and vendor advisories rather than public exploit code.
What to do
- Upgrade Node.js to 10.24.0, 12.21.0, 14.16.0, 15.10.0 or later, per the Node.js February 2021 security release.
- Apply vendor patches for downstream products (Oracle, NetApp, Siemens, Fedora) that bundle the affected Node.js.
- Set and monitor OS file descriptor limits (ulimit/nofile) for Node.js processes so exhaustion is bounded and visible.
- Rate-limit or filter connection attempts that fail protocol negotiation at the load balancer or reverse proxy.
- Restart or recycle Node.js workers showing descriptor or memory growth until patched.
Detection
- Monitor Node.js process file descriptor counts and open handles for sustained growth without matching traffic increases.
- Alert on spikes in connections that fail protocol negotiation or produce unknownProtocol errors in server logs.
- Track memory growth and out-of-memory events on Node.js hosts alongside connection rate.
- Watch for repeated connection attempts from single sources against TLS or protocol-negotiating ports.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-22883 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22883), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.