CVE-2022-1434

Cryptographic Weakness
Affects
Node.js
in
Node.js
No items found.
Versions
>=17.0.0 <17.9.1 >=18.0.0 <18.2.0

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js compiles its own copy of OpenSSL from deps/openssl in the Node.js source tree, and the built-in tls and https modules sit on top of that bundled copy. Node.js 17.x was the first release line to bundle OpenSSL 3.0.

A vulnerability (CVE-2022-1434) has been identified in the OpenSSL 3.0 library bundled with Node.js. OpenSSL 3.0's implementation of the RC4-MD5 TLS cipher suite uses the record's additional authenticated data (AAD) as the MAC key instead of the real secret key. Because the AAD is predictable, a man-in-the-middle attacker can modify data in transit so that it still passes the MAC integrity check.

This flaw maps to CWE-327 (Use of a Broken or Risky Cryptographic Algorithm), where software relies on a cryptographic mechanism that does not provide the protection it is meant to. In OpenSSL 3.0, a copy-and-paste error turned RC4-MD5's integrity check into one an attacker can compute. Confidentiality is not affected: the attacker cannot decrypt the traffic, only alter it undetected.

The attack only works when both endpoints legitimately negotiate RC4-MD5, which OpenSSL 3.0 does not offer by default. OpenSSL must have been compiled with the non-default enable-weak-ssl-ciphers option, the legacy provider must be loaded, RC4-MD5 must be explicitly added to the cipher list, the security level must be set to 0, a protocol older than TLS 1.3 must be in use, and both peers must prefer RC4-MD5 over every other cipher they share. When only one side runs OpenSSL 3.0, data it sends is rejected by the other side, so typically only an OpenSSL 3.0 server talking to an older client is exposed; when both sides run OpenSSL 3.0, data in both directions can be modified. This issue affects the Node.js 17.x and 18.x release lines up to the versions listed above.

‍

Details

Module Info

  • Product: Node.js
  • Affected packages: node (bundles OpenSSL 3.0 under deps/openssl)
  • Affected versions: >=17.0.0 <17.9.1 >=18.0.0 <18.2.0
  • GitHub repository: https://github.com/nodejs/node
  • Published packages: https://nodejs.org/en/download
  • Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
  • Fixed in: Node.js 18.2.0 (May 17, 2022) and 17.9.1 (June 1, 2022), which upgraded the bundled OpenSSL to 3.0.3; this CVE is also listed in the Node.js NES v16.20.3 release notes (16.x line, shipped July 30, 2024)

Vulnerability Info

This Medium-severity vulnerability is found in OpenSSL 3.0.0 through 3.0.2, the versions bundled by Node.js 17.x and 18.x before the releases listed above. NVD assigns a CVSS v3.1 score of 5.9; OpenSSL rates the issue Low under its own severity policy.

In a TLS cipher suite that uses a separate MAC, each record's integrity tag is computed with a secret MAC key derived during the handshake. In OpenSSL 3.0, the RC4-MD5 code passed the TLS AAD, data an observer can predict, where the MAC key belonged. An attacker positioned between the peers can therefore compute valid tags for modified records. The fix passes the correct key. See the OpenSSL fix commit for the exact change.

Exploitation requires a man-in-the-middle position on a connection where both peers have deliberately enabled and chosen RC4-MD5, a cipher suite that is disabled at build time and at run time by default. Without an attacker, the same bug simply makes handshakes between an OpenSSL 3.0 endpoint and a different TLS implementation fail on this cipher suite.

Note: The official Node.js builds do not compile OpenSSL with enable-weak-ssl-ciphers, so RC4-MD5 cannot be negotiated by them. Applications are only exposed on a Node.js build whose OpenSSL was compiled with that option and configured as described above.

‍

Mitigation

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, which includes this fix.
  • Do not enable RC4-MD5 or any RC4 cipher suite; keep the default cipher list and security level.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.

‍

Credits

  • Tom Colley from Broadcom (reporter)
  • Matt Caswell from the OpenSSL project (remediation developer)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Medium
ID
CVE-2022-1434
PROJECT Affected
Node.js
Versions Affected
>=17.0.0 <17.9.1 >=18.0.0 <18.2.0
NES Versions Affected
Published date
October 1, 2026
≈ Fix date
July 30, 2024
Category
Cryptographic Weakness
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Node.js
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.