CVE-2022-43548

Remote Code Execution
Affects
Node.js
in
Node.js
No items found.
Versions
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.21.1 >=15.0.0 <=15.14.0 >=16.0.0 <16.18.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.12.1 >=19.0.0 <19.0.1

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. When started with --inspect, Node.js opens a debugging server that accepts connections over HTTP and WebSocket, and any client that connects to it can run arbitrary code inside the process. To keep web pages from reaching that server, Node.js checks the HTTP Host header of each request and only accepts localhost or a literal IP address.

A vulnerability (CVE-2022-43548) has been identified in Node.js's inspector host check. The check accepted IP addresses written with an invalid octal component, such as 1.09.0.0, as IP addresses. Some browsers, including Firefox, treat such a string as a host name and resolve it through DNS, so a malicious web page can use DNS rebinding to send requests to the local inspector that the check lets through, and then execute arbitrary code on the developer's machine.

The CVE record classifies this as CWE-78 (OS Command Injection), reflecting its end result, where an attacker gets commands executed on the target system; the underlying defect is a bypass of DNS rebinding protection. In Node.js, the inspector relied on IsIPAddress() to tell literal IP addresses, which DNS cannot change, apart from host names, which an attacker's DNS server can point anywhere. Because IsIPAddress() accepted a string that a browser would still look up in DNS, the protection against rebinding could be bypassed, and access to the inspector amounts to code execution in the Node.js process.

An attacker needs the victim to have an active --inspect session, which is common during development, for example when debugging from VS Code, and to open a web page the attacker controls in a browser that resolves invalid octal addresses through DNS. This is an incomplete-fix follow-up to CVE-2022-32212, which first hardened the same check. This issue affects every Node.js release line from 4.x through 19.x up to the versions listed above.

Details

Module Info

  • Product: Node.js
  • Affected packages: node (inspector, src/inspector_socket.cc)
  • Affected versions: >=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.21.1 >=15.0.0 <=15.14.0 >=16.0.0 <16.18.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.12.1 >=19.0.0 <19.0.1
  • GitHub repository: https://github.com/nodejs/node
  • Published packages: https://nodejs.org/en/download
  • Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
  • Fixed in: Node.js 18.12.1 (November 3, 2022) and 14.21.1, 16.18.1 and 19.0.1 (November 4, 2022), the Node.js November 2022 security releases; Node.js NES v12.22.18 (12.x line, shipped April 28, 2026), which cherry-picks the fix for the 12.x line, which never received it upstream. The other release lines listed above never received a fix

Vulnerability Info

This High-severity vulnerability is found in the Node.js inspector's Host header validation in src/inspector_socket.cc. NVD assigns a CVSS v3.1 score of 8.1; the Node.js project rated it Medium in its security release.

When a request reaches the inspector, Node.js compares the Host header against an allowlist: the request is accepted only if the host is localhost or an IP address, because DNS rebinding works by pointing a host name the attacker controls at 127.0.0.1. In the vulnerable versions, IsIPAddress() used a hand-written parser that accepted dotted strings such as 1.09.0.0 as IPv4 addresses even though 09 is not a valid octal number, while browsers that also reject that form fall back to resolving it as a host name. The fix replaces the hand-written parser with inet_pton(), which accepts only well-defined address formats and rejects octal, hexadecimal and leading-zero forms, and it also rejects the non-routable 0.0.0.0/8 and :: addresses. See the Node.js fix commit for the exact change.

The attack chain is: the victim visits the attacker's page, the page makes requests to the invalid octal host name, the attacker's DNS server first answers with its own address and then with 127.0.0.1, and the browser's requests reach the inspector with a Host header that passes the check. From there the attacker can open an inspector session and run code with the privileges of the Node.js process.

Note: Node.js processes started without --inspect, --inspect-brk or an equivalent, or whose inspector was never activated at run time, are not exposed by this issue.

Mitigation

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which include this fix.
  • Where an upgrade is not yet possible, do not run Node.js with --inspect while browsing untrusted sites, and never expose the inspector port outside the local machine.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.

Credits

  • haxatron1 (reporter)
  • Tobias Nießen (remediation developer)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
High
ID
CVE-2022-43548
PROJECT Affected
Node.js
Versions Affected
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.21.1 >=15.0.0 <=15.14.0 >=16.0.0 <16.18.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.12.1 >=19.0.0 <19.0.1
NES Versions Affected
Published date
October 8, 2026
≈ Fix date
April 28, 2026
Category
Remote Code Execution
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Node.js
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.