CVE-2022-1473

Uncontrolled Resource Consumption
Affects
Node.js
in
Node.js
No items found.
Versions
>=17.0.0 <17.9.1 >=18.0.0 <18.2.0

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js compiles its own copy of OpenSSL from deps/openssl in the Node.js source tree, and the built-in crypto, tls and https modules sit on top of that bundled copy. Node.js 17.x was the first release line to bundle OpenSSL 3.0.

A vulnerability (CVE-2022-1473) has been identified in the OpenSSL 3.0 library bundled with Node.js. OpenSSL's OPENSSL_LH_flush() function, which empties an internal hash table, leaves the table believing it still holds the entries it just removed, so the memory they occupied is never reused. OpenSSL calls this function while decoding certificates and keys, so a long-running process that keeps decoding them grows its memory use without limit until the operating system may terminate it.

This flaw maps to CWE-459 (Incomplete Cleanup), where software does not fully reset a resource after use, leaving it in a state that keeps consuming memory or causes later misbehavior. In OpenSSL 3.0, the hash table's item count is not reset when it is flushed. Each round of certificate or key decoding therefore adds to memory that is never reclaimed, and walking the growing table of empty entries also takes progressively more time, eventually leading to a denial of service.

A remote attacker can drive the leak in any long-lived Node.js process that decodes certificates or keys on the attacker's behalf: TLS servers that accept client certificates, TLS clients that repeatedly connect to servers the attacker controls, or applications that parse user-supplied certificates or keys through the crypto module. No privileges or user interaction are needed; the attacker only has to keep supplying input to decode. This issue affects the Node.js 17.x and 18.x release lines up to the versions listed above.

‍

Details

Module Info

  • Product: Node.js
  • Affected packages: node (bundles OpenSSL 3.0 under deps/openssl)
  • Affected versions: >=17.0.0 <17.9.1 >=18.0.0 <18.2.0
  • GitHub repository: https://github.com/nodejs/node
  • Published packages: https://nodejs.org/en/download
  • Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
  • Fixed in: Node.js 18.2.0 (May 17, 2022) and 17.9.1 (June 1, 2022), which upgraded the bundled OpenSSL to 3.0.3; this CVE is also listed in the Node.js NES v16.20.3 release notes (16.x line, shipped July 30, 2024)

Vulnerability Info

This High-severity vulnerability is found in OpenSSL 3.0.0 through 3.0.2, the versions bundled by Node.js 17.x and 18.x before the releases listed above. NVD assigns a CVSS v3.1 score of 7.5; OpenSSL rates the issue Low under its own severity policy, and the Node.js project likewise assessed its impact on Node.js 17.x and 18.x as Low.

OpenSSL keeps temporary lookup data in a hash table while it decodes a certificate or key, and flushes that table when it is done. A correct flush frees every entry and resets the table's item count so the space can be reused. In the vulnerable versions, OPENSSL_LH_flush() freed the entries but left the item count unchanged, so the table kept sizing itself as if it were still full and memory grew with every decode. The fix resets the count to zero. See the OpenSSL fix commit for the exact change.

An attacker cannot trigger this with a single request; the damage accumulates over many decode operations in the same process. Servers that request client certificates and clients that open many connections are the typical targets, and the result is rising memory use and slowing certificate handling until the process is killed or restarted.

Note: OpenSSL 1.1.1 and older do not contain this function, so Node.js release lines that bundle OpenSSL 1.1.1, including 16.x and earlier, are not affected by this issue.

‍

Mitigation

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, which includes this fix.
  • Migrate affected applications away from the End-of-Life Node.js release lines.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.

‍

Credits

  • Aliaksei Levin (reporter)
  • Hugo Landau from the OpenSSL project (remediation developer)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
High
ID
CVE-2022-1473
PROJECT Affected
Node.js
Versions Affected
>=17.0.0 <17.9.1 >=18.0.0 <18.2.0
NES Versions Affected
Published date
October 1, 2026
≈ Fix date
July 30, 2024
Category
Uncontrolled Resource Consumption
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Node.js
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.