CVE-2023-0464
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js compiles its own copy of OpenSSL from deps/openssl in the Node.js source tree, and the built-in tls and https modules rely on that bundled copy to verify certificate chains. A flaw in the bundled OpenSSL therefore reaches Node.js directly.
A vulnerability (CVE-2023-0464) has been identified in the OpenSSL library bundled with Node.js. When OpenSSL verifies an X.509 certificate chain that includes policy constraints, a malicious chain can make the policy-processing code use computational resources that grow exponentially, leading to a denial of service.
This flaw maps to CWE-407 (Inefficient Algorithmic Complexity), where an algorithm's worst-case cost can be driven far above its normal cost by crafted input. In OpenSSL, X.509 policy checking builds a tree of policy nodes, one level per certificate in the chain. The tree had no size limit, so a chain built to make each level multiply the nodes of the one before forced OpenSSL to create and evaluate an exponentially large tree.
Policy processing is disabled by default in OpenSSL and is only active when an application passes -policy to the command-line tools or calls X509_VERIFY_PARAM_set1_policies(). Node.js's built-in tls and https modules never enable it, so exposure in a Node.js deployment depends on native addons or embedders that turn policy checking on through the bundled OpenSSL. In those cases, an attacker who can present a certificate chain, such as a malicious TLS server or a client presenting a certificate, can trigger the issue. This issue affects every Node.js release line from 4.x through 20.x whose bundled OpenSSL is 1.0.2, 1.1.1 or 3.0, up to the versions listed above.
Details
Module Info
- Product: Node.js
- Affected packages: node (bundles OpenSSL under deps/openssl)
- Affected versions: >=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.20.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.16.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.3.1
- GitHub repository: https://github.com/nodejs/node
- Published packages: https://nodejs.org/en/download
- Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
- Fixed in: Node.js 16.20.1, 18.16.1 and 20.3.1 (all June 20, 2023), security releases that upgraded the bundled OpenSSL to 1.1.1u or 3.0.9; Node.js NES v14.21.4 (14.x line, shipped August 24, 2024) and v12.22.13 (12.x line, shipped November 10, 2025), neither of which received an upstream fix; NES also lists v16.20.3 (16.x line, shipped July 30, 2024), a later cumulative build carrying the same fix already shipped upstream in 16.20.1. The other release lines listed above never received an updated OpenSSL
Vulnerability Info
This High-severity vulnerability is found in the OpenSSL library that Node.js bundles and statically links at deps/openssl, in Node.js releases whose bundled OpenSSL predates 1.1.1u, 3.0.9 or 1.0.2zh. NVD assigns a CVSS v3.1 score of 7.5; OpenSSL rates the issue Low under its own severity policy, mainly because policy processing is off by default.
When policy checking is enabled, OpenSSL turns the certificate policies and policy mappings in each certificate of the chain into a policy tree, then walks that tree to decide whether the chain satisfies the required policies. Each certificate can add nodes for every policy it asserts or maps, so a chain whose certificates assert and map many policies can make the tree grow exponentially with the chain's length. In the vulnerable versions, nothing bounded that growth. The fix counts the nodes as the tree is built and stops with an error once a fixed maximum is reached. See the OpenSSL 1.1.1 fix commit and the OpenSSL 3.0 fix commit for the exact changes.
On an affected application, a single crafted certificate chain can tie up CPU and memory for a long time, making the process unresponsive. The chain does not need to be trusted, since policy processing happens during verification.
Note: Because policy processing is off by default and Node.js does not enable it, applications that never call X509_VERIFY_PARAM_set1_policies() or pass -policy are not exposed by this issue.
Mitigation
Users of the affected components should apply one of the following mitigations:
- Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, which includes this fix.
- Migrate affected applications away from the End-of-Life Node.js release lines.
- Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.
Credits
- David Benjamin from Google (reporter)
- Dr Paul Dale from the OpenSSL project (remediation developer)