Vulnerability record · CVE-2021-44531 · published 24 February 2022
CVE-2021-44531: Nodejs node.js improper certificate validation vulnerability
Nodejs · Node.Js
Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are often not defined to use. Additionally, when a protocol allows URI SANs, Node.js did not match the URI correctly.Versions of Node.js with the fix for this disable the URI SAN type when checking a certificate against a hostname. This behavior can be reverted through the --security-revert command-line option.
Description
Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are often not defined to use. Additionally, when a protocol allows URI SANs, Node.js did not match the URI correctly.Versions of Node.js with the fix for this disable the URI SAN type when checking a certificate against a hostname. This behavior can be reverted through the --security-revert command-line option.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://hackerone.com/reports/1429694 | Issue TrackingMitigationPatchThird Party Advisory |
| https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/ | Release NotesVendor Advisory |
| https://security.netapp.com/advisory/ntap-20220325-0007/ | Third Party Advisory |
| https://www.debian.org/security/2022/dsa-5170 | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2022.html | Third Party Advisory |
| https://hackerone.com/reports/1429694 | Issue TrackingMitigationPatchThird Party Advisory |
| https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/ | Release NotesVendor Advisory |
| https://security.netapp.com/advisory/ntap-20220325-0007/ | Third Party Advisory |
| https://www.debian.org/security/2022/dsa-5170 | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2022.html | Third Party Advisory |
Track CVE-2021-44531 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-44531), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.