CVE-2023-3817
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js compiles its own copy of OpenSSL from deps/openssl in the Node.js source tree and statically links it into the runtime, and the built-in crypto module uses that bundled copy for Diffie-Hellman (DH) key exchange, including checking DH parameters.
A vulnerability (CVE-2023-3817) has been identified in the OpenSSL library bundled with Node.js. OpenSSL's DH_check() function, which validates DH parameters, can run for a very long time when the parameters include an excessively large q value. An application that checks DH keys or parameters obtained from an untrusted source with DH_check(), DH_check_ex() or EVP_PKEY_param_check() can be slowed down enough to cause a denial of service.
This flaw maps to CWE-606 (Unchecked Input for Loop Condition), where the amount of work a loop does is controlled by input that is never checked, and to CWE-834 (Excessive Iteration). DH parameters include a prime modulus p and, optionally, a subgroup order q, and a valid q can never be larger than p. DH_check() ran expensive computations on q without first confirming that it was smaller than p, so an oversized q made those computations take as long as the attacker wanted.
This issue was found after the related fix for CVE-2023-3446, which addressed the same kind of slowdown for an oversized modulus p. OpenSSL's TLS implementation is not affected, and neither are OpenSSL's FIPS providers. Node.js does call DH_check() when a crypto.DiffieHellman object is created, to compute its verifyError property, but the built-in API only accepts a prime and a generator and always leaves q empty, so the vulnerable q checks are never reached through it. Exposure in a Node.js deployment depends on native addons or embedders that check untrusted DH parameters containing q. This issue affects every Node.js release line from 4.x through 20.x up to the versions listed above.
Details
Module Info
- Product: Node.js
- Affected packages: node (bundles OpenSSL under deps/openssl)
- Affected versions: >=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.20.2 >=17.0.0 <=17.9.1 >=18.0.0 <18.17.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.5.1
- GitHub repository: https://github.com/nodejs/node
- Published packages: https://nodejs.org/en/download
- Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
- Fixed in: Node.js 16.20.2, 18.17.1 and 20.5.1 (all August 9, 2023), security releases that upgraded the bundled OpenSSL to 1.1.1v or 3.0.10; Node.js NES v14.21.4 (14.x line, shipped August 24, 2024) and v12.22.13 (12.x line, shipped November 10, 2025), neither of which received an upstream fix; NES also lists v16.20.3 (16.x line, shipped July 30, 2024), a later cumulative build carrying the same fix already shipped upstream in 16.20.2. The other release lines listed above never received an updated OpenSSL
Vulnerability Info
This Medium-severity vulnerability is found in the OpenSSL library that Node.js bundles and statically links at deps/openssl, in Node.js releases whose bundled OpenSSL predates 1.1.1v, 3.0.10 or the 1.0.2 premium-support fix. NVD assigns a CVSS v3.1 score of 5.3; OpenSSL rates the issue Low under its own severity policy.
When DH parameters include q, DH_check() runs several tests on it, including primality testing and checking that the generator has order q, and the cost of those tests grows with the size of q. In the vulnerable versions, DH_check() ran them on whatever q it was given, however large. The fix first compares q with p: if q is not smaller than p, DH_check() reports the parameters as invalid and skips the expensive q tests entirely. See the OpenSSL 1.1.1 fix commit and the OpenSSL 3.0 fix commit for the exact changes.
An attacker needs to get DH parameters or a DH key with an oversized q checked by an application, for example by submitting them to a service that validates uploaded parameters. The OpenSSL dhparam and pkeyparam command-line tools are also affected when used with -check. The result is long CPU-bound delays in the checking process.
Note: OpenSSL's TLS implementation does not call the affected checks, so TLS connections are not a route to this issue, and Node.js's built-in crypto.createDiffieHellman() never passes a q value to DH_check().
Mitigation
Users of the affected components should apply one of the following mitigations:
- Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, which includes this fix.
- Migrate affected applications away from the End-of-Life Node.js release lines.
- Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.
Credits
- Bernd Edlinger (finder)
- Tomáš Mráz from the OpenSSL project (remediation developer)