← Vulnerability feed

Vulnerability record · CVE-2021-22883 · published 3 March 2021

CVE-2021-22883: Node.js unknownProtocol connection flood leaks file descriptors

Nodejs · Node.Js

Node.js before 10.24.0, 12.21.0, 14.16.0 and 15.10.0 leaks file descriptors when many connection attempts using an 'unknownProtocol' are established. Repeated attempts exhaust the file descriptor limit or, where no limit is set, drive excessive memory use until the process or host runs out of resources. It matters because a remote unauthenticated client can take a Node.js service offline.

7.5 CVSS 3.1 High EPSS 74% · top 0.5% CWE-400 · Uncontrolled resource consumptionCWE-772 · CWE-772
7.5CVSS 3.1 base score, v2 7.8
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
20References
17 Jun 2026Last modified by NVD

Description

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote unauthenticated denial of service with a CVSS of 7.5 and very high EPSS, though no KEV listing or known exploit code.

What it is

Node.js before 10.24.0, 12.21.0, 14.16.0 and 15.10.0 leaks file descriptors when many connection attempts using an 'unknownProtocol' are established. Repeated attempts exhaust the file descriptor limit or, where no limit is set, drive excessive memory use until the process or host runs out of resources. It matters because a remote unauthenticated client can take a Node.js service offline.

Impact

An attacker can exhaust file descriptors or memory on the Node.js process, causing it to stop accepting new connections and to fail opening files, resulting in denial of service.

Attack surface

Reachable over the network against a listening Node.js service; the CVSS vector shows no privileges and no user interaction required. The flaw triggers on connection attempts that negotiate an unknown protocol, so any exposed TLS or protocol-negotiating endpoint is a candidate.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.74352, 99.467th percentile), indicating elevated likelihood of attempted exploitation. References include patch and vendor advisories rather than public exploit code.

What to do

  • Upgrade Node.js to 10.24.0, 12.21.0, 14.16.0, 15.10.0 or later, per the Node.js February 2021 security release.
  • Apply vendor patches for downstream products (Oracle, NetApp, Siemens, Fedora) that bundle the affected Node.js.
  • Set and monitor OS file descriptor limits (ulimit/nofile) for Node.js processes so exhaustion is bounded and visible.
  • Rate-limit or filter connection attempts that fail protocol negotiation at the load balancer or reverse proxy.
  • Restart or recycle Node.js workers showing descriptor or memory growth until patched.

Detection

  • Monitor Node.js process file descriptor counts and open handles for sustained growth without matching traffic increases.
  • Alert on spikes in connections that fail protocol negotiation or produce unknownProtocol errors in server logs.
  • Track memory growth and out-of-memory events on Node.js hosts alongside connection rate.
  • Watch for repeated connection attempts from single sources against TLS or protocol-negotiating ports.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf PatchThird Party Advisory
https://hackerone.com/reports/1043360 Permissions RequiredThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4FRS5ZVK4ZQ7XIJQNGIKUX
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F45Y7TXSU33MTKB6AGL2Q5V
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSYFUGKFUSZ27M5TEZ3FKIL
https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/ PatchRelease NotesVendor Advisory
https://security.netapp.com/advisory/ntap-20210416-0001/ Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf PatchThird Party Advisory
https://hackerone.com/reports/1043360 Permissions RequiredThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4FRS5ZVK4ZQ7XIJQNGIKUX
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F45Y7TXSU33MTKB6AGL2Q5V
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSYFUGKFUSZ27M5TEZ3FKIL
https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/ PatchRelease NotesVendor Advisory
https://security.netapp.com/advisory/ntap-20210416-0001/ Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory

Track CVE-2021-22883 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2021-22883), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.