CVE-2022-0778

Denial of Service
Affects
Node.js
in
Node.js
No items found.
Versions
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <12.22.11 >=13.0.0 <=13.14.0 >=14.0.0 <14.19.1 >=15.0.0 <=15.14.0 >=16.0.0 <16.14.2 >=17.0.0 <17.7.2

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js does not rely on a system cryptography library by default: it compiles its own copy of OpenSSL from deps/openssl in the Node.js source tree, and the built-in crypto, tls and https modules sit on top of that bundled copy. A flaw in the bundled OpenSSL therefore reaches Node.js directly.

A vulnerability (CVE-2022-0778) has been identified in the OpenSSL library bundled with Node.js. OpenSSL's BN_mod_sqrt() function, which computes a modular square root, can loop forever when given a non-prime modulus. OpenSSL calls it while parsing certificates and private keys that carry elliptic-curve keys or curve parameters in compressed form, so a crafted certificate with invalid explicit curve parameters can hang the process that parses it.

This flaw maps to CWE-835 (Loop with Unreachable Exit Condition, 'Infinite Loop'), where a loop's exit condition can never be met. In OpenSSL, BN_mod_sqrt() assumes its modulus is prime and has no way out of its search when it is not. Because Node.js runs JavaScript on a single main thread, a hang inside certificate parsing stops the whole process from serving requests, resulting in a denial of service.

Certificate parsing happens before the certificate's signature is verified, so an attacker does not need a trusted certificate: any process that parses a certificate it receives from outside can be targeted. That covers Node.js TLS clients connecting to a malicious server, TLS servers that request client certificates, and applications that parse user-supplied certificates, certificate requests or private keys, for example through the crypto module. This issue affects every Node.js release line from 4.x through 17.x up to the versions listed above, since all of them bundled an affected OpenSSL 1.0.2, 1.1.0, 1.1.1 or 3.0 release.

‍

Details

Module Info

  • Product: Node.js
  • Affected packages: node (bundles OpenSSL under deps/openssl)
  • Affected versions: >=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <12.22.11 >=13.0.0 <=13.14.0 >=14.0.0 <14.19.1 >=15.0.0 <=15.14.0 >=16.0.0 <16.14.2 >=17.0.0 <17.7.2
  • GitHub repository: https://github.com/nodejs/node
  • Published packages: https://nodejs.org/en/download
  • Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
  • Fixed in: Node.js 12.22.11, 14.19.1, 16.14.2 and 17.7.2 (all March 17, 2022), security releases that upgraded the bundled OpenSSL to 1.1.1n or 3.0.2; Node.js NES v16.20.3 (16.x line, shipped July 30, 2024), a later cumulative build carrying the same fix. Node.js 4.x through 11.x, 13.x and 15.x never received a fix

Vulnerability Info

This High-severity vulnerability is found in the OpenSSL library that Node.js bundles and statically links at deps/openssl, in every Node.js release whose bundled OpenSSL predates 1.1.1n, 3.0.2 or 1.0.2zd. NVD assigns a CVSS v3.1 score of 7.5, and both OpenSSL and the Node.js security release rate the issue High.

When OpenSSL decodes an elliptic-curve point stored in compressed form, it has to recover the missing coordinate by taking a modular square root, which only terminates correctly when the modulus is prime. Valid curves always use a prime field, but explicit curve parameters inside a certificate or key are attacker-controlled, and the vulnerable BN_mod_sqrt() kept iterating forever on a non-prime value instead of failing. The fix adds a bound to that loop so a bad modulus produces an error. See the OpenSSL 1.1.1 fix commit for the exact change.

An attacker only needs to get a crafted certificate or key in front of the vulnerable code: by running a TLS server a Node.js client connects to, by presenting a client certificate to a Node.js server that asks for one, or by submitting the file to an application that parses it. Each such parse pins a CPU core and blocks the Node.js event loop, so a single connection is enough to make the process unresponsive.

Note: On the OpenSSL 1.0.2 line bundled by Node.js 4.x through 9.x, the public key is not decoded during initial certificate parsing, which makes the loop slightly harder to reach. Any operation that needs the certificate's public key still triggers it, and a self-signed certificate triggers it during signature verification.

‍

Mitigation

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, which includes this fix.
  • Migrate affected applications away from the End-of-Life Node.js release lines.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.

‍

Credits

  • Tavis Ormandy from Google (reporter)
  • David Benjamin from Google (remediation developer)
  • Tomáš Mráz from the OpenSSL project (remediation developer)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
High
ID
CVE-2022-0778
PROJECT Affected
Node.js
Versions Affected
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <12.22.11 >=13.0.0 <=13.14.0 >=14.0.0 <14.19.1 >=15.0.0 <=15.14.0 >=16.0.0 <16.14.2 >=17.0.0 <17.7.2
NES Versions Affected
Published date
October 1, 2026
≈ Fix date
July 30, 2024
Category
Denial of Service
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Node.js
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.