CVE-2023-2650

Inefficient Algorithmic Complexity
Affects
Node.js
in
Node.js
No items found.
Versions
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.20.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.16.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.3.1

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js compiles its own copy of OpenSSL from deps/openssl in the Node.js source tree, and the built-in crypto, tls and https modules rely on that bundled copy to parse, verify and describe X.509 certificates.

A vulnerability (CVE-2023-2650) has been identified in the OpenSSL library bundled with Node.js. OpenSSL's OBJ_obj2txt() function, which turns an ASN.1 object identifier (OID) into its dotted numeric text form, takes time that grows with the square of a sub-identifier's size. An attacker who supplies an OID with an absurdly large sub-identifier, tens or hundreds of kilobytes long, can make that translation take seconds to minutes, which may lead to a denial of service.

This flaw maps to CWE-407 (Inefficient Algorithmic Complexity), where an algorithm's worst-case cost can be driven far above its normal cost by crafted input. An OID is a series of numbers with no fixed size limit, and OBJ_obj2txt() converted each one to decimal with an O(n^2) algorithm. OpenSSL measured roughly 2 seconds for a 100 KiB sub-identifier and about a minute for 500 KiB.

How much this matters depends on the OpenSSL version. On OpenSSL 3.0, which Node.js bundles from 17.x onward, algorithm identifiers can be looked up by OID text, so the slow path also runs while processing X.509 certificates, including verifying a certificate's signature; TLS is less exposed because peer certificate chains are capped at 100 KiB, and only clients and servers that request client certificates process a peer chain. On OpenSSL 1.1.1 and 1.0.2, only direct calls to OBJ_obj2txt() are affected. Node.js makes such direct calls when it reports a certificate's extended key usage OIDs and registered-ID subject alternative names, for example through tlsSocket.getPeerCertificate() or crypto.X509Certificate. This issue affects every Node.js release line from 4.x through 20.x up to the versions listed above.

Details

Module Info

  • Product: Node.js
  • Affected packages: node (bundles OpenSSL under deps/openssl)
  • Affected versions: >=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.20.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.16.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.3.1
  • GitHub repository: https://github.com/nodejs/node
  • Published packages: https://nodejs.org/en/download
  • Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
  • Fixed in: Node.js 16.20.1, 18.16.1 and 20.3.1 (all June 20, 2023), security releases that upgraded the bundled OpenSSL to 1.1.1u or 3.0.9; Node.js NES v14.21.4 (14.x line, shipped August 24, 2024) and v12.22.13 (12.x line, shipped November 10, 2025), neither of which received an upstream fix; NES also lists v16.20.3 (16.x line, shipped July 30, 2024), a later cumulative build carrying the same fix already shipped upstream in 16.20.1. The other release lines listed above never received an updated OpenSSL

Vulnerability Info

This Medium-severity vulnerability is found in the OpenSSL library that Node.js bundles and statically links at deps/openssl, in Node.js releases whose bundled OpenSSL predates 1.1.1u, 3.0.9 or 1.0.2zh. NVD assigns a CVSS v3.1 score of 6.5; OpenSSL rates the issue Moderate for OpenSSL 3.0 and Low for 1.1.1 and 1.0.2, where only direct callers are affected.

OBJ_obj2txt() decodes each sub-identifier of an OID from its base-128 DER encoding and prints it in decimal. For a sub-identifier of n bytes, that conversion took time proportional to n squared, and nothing limited how large a sub-identifier could be. The fix limits the OIDs that OBJ_obj2txt() will translate to numeric form to the bounds in RFC 2578: at most 128 sub-identifiers, each no larger than 2^32-1. See the OpenSSL 1.1.1 fix commit and the OpenSSL 3.0 fix commit for the exact changes.

An attacker needs to get a crafted OID processed: inside a certificate presented to a Node.js TLS client or to a server that requests client certificates, inside a certificate an application parses or inspects, or inside OCSP, PKCS#7/SMIME, CMS, CMP/CRMF or time stamp data on OpenSSL 3.0. NVD's vector assumes the victim takes an action, such as connecting to a malicious server. Each crafted OID blocks the thread doing the work, which in Node.js is the event loop.

Note: OpenSSL's FIPS provider is not affected in any version. On Node.js release lines that bundle OpenSSL 1.1.1 or 1.0.2, applications that never read extended key usage or subject alternative names from untrusted certificates do not reach the affected code.

Mitigation

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, which includes this fix.
  • Migrate affected applications away from the End-of-Life Node.js release lines.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.

Credits

  • OSS-Fuzz (reporter; first detected the issue in January 2020)
  • Matt Caswell from the OpenSSL project (reporter; identified it as a security issue in April 2023)
  • Richard Levitte from the OpenSSL project (remediation developer)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Medium
ID
CVE-2023-2650
PROJECT Affected
Node.js
Versions Affected
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.20.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.16.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.3.1
NES Versions Affected
Published date
October 8, 2026
≈ Fix date
July 30, 2024
Category
Inefficient Algorithmic Complexity
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Node.js
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.