CVE-2023-0216

Denial of Service
Affects
Node.js
in
Node.js
No items found.
Versions
>=17.0.0 <=17.9.1 >=18.0.0 <18.14.1 >=19.0.0 <19.6.1

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js compiles its own copy of OpenSSL from deps/openssl in the Node.js source tree and statically links it into the runtime, so a flaw in the bundled OpenSSL is present in every Node.js binary built from that tree. Node.js 17.x was the first release line to bundle OpenSSL 3.0.

A vulnerability (CVE-2023-0216) has been identified in the OpenSSL 3.0 library bundled with Node.js. When an application loads malformed PKCS#7 data with d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp(), OpenSSL can dereference an invalid pointer while reading, which crashes the process and can be used for a denial of service attack.

This flaw maps to CWE-476 (NULL Pointer Dereference), where software uses a pointer it expects to be valid when it is actually NULL. In OpenSSL 3.0, the step that runs after a PKCS#7 structure is parsed assumed the structure's content field was always present. PKCS#7 data that parses successfully but carries no content leaves that field empty, and the follow-up step reads through it anyway.

An attacker needs an application that passes untrusted PKCS#7 data to one of the affected functions. OpenSSL's TLS implementation does not call them, so TLS connections are not a route to this flaw. Node.js's built-in modules do not call them either, so exposure in a Node.js deployment depends on native addons or embedders that parse PKCS#7 through the bundled OpenSSL. This issue affects the Node.js 17.x, 18.x and 19.x release lines up to the versions listed above.

Details

Module Info

  • Product: Node.js
  • Affected packages: node (bundles OpenSSL 3.0 under deps/openssl)
  • Affected versions: >=17.0.0 <=17.9.1 >=18.0.0 <18.14.1 >=19.0.0 <19.6.1
  • GitHub repository: https://github.com/nodejs/node
  • Published packages: https://nodejs.org/en/download
  • Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
  • Fixed in: Node.js 18.14.1 and 19.6.1 (February 16, 2023), security releases that upgraded the bundled OpenSSL to 3.0.8; this CVE is also listed in the Node.js NES v16.20.3 release notes (16.x line, shipped July 30, 2024). Node.js 17.x never received a fix

Vulnerability Info

This High-severity vulnerability is found in OpenSSL 3.0.0 through 3.0.7, the versions bundled by Node.js 17.x, 18.x and 19.x before the releases listed above. NVD assigns a CVSS v3.1 score of 7.5; OpenSSL rates the issue Moderate under its own severity policy.

OpenSSL 3.0 added a step to the d2i_PKCS7 functions: once a PKCS#7 structure is decoded, ossl_pkcs7_resolve_libctx() walks its signer certificates and recipient information to attach the library context that later cryptographic operations need. Those lookups read through the structure's content pointer, which is empty when the decoded data has no content. In the vulnerable versions, nothing checked for that case, so the lookups dereferenced an invalid pointer. The fix makes ossl_pkcs7_resolve_libctx() and the helper functions it uses return early when the content pointer is not set. See the OpenSSL fix commit for the exact change.

A single malformed PKCS#7 blob passed to an affected function is enough to crash the process. The flaw is a read through an invalid pointer and is not known to allow code execution or data disclosure.

Note: OpenSSL 1.1.1 and 1.0.2 are not affected, so Node.js release lines that bundle them, including 16.x and earlier, are not exposed by this issue. Node.js applications that rely only on the built-in crypto, tls and https modules do not call the affected functions.

Mitigation

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, which includes this fix.
  • Migrate affected applications away from the End-of-Life Node.js release lines.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.

Credits

  • Marc Schönefeld (reporter)
  • Tomáš Mráz from the OpenSSL project (remediation developer)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
High
ID
CVE-2023-0216
PROJECT Affected
Node.js
Versions Affected
>=17.0.0 <=17.9.1 >=18.0.0 <18.14.1 >=19.0.0 <19.6.1
NES Versions Affected
Published date
October 8, 2026
≈ Fix date
July 30, 2024
Category
Denial of Service
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Node.js
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.