CVE-2026-21637
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, and it is widely used for web applications and server-side development.
A denial-of-service vulnerability (CVE-2026-21637) exists in Node.js's own built-in TLS implementation (lib/_tls_wrap.js). This is Node.js's own runtime code, not a flaw in a bundled third-party library such as OpenSSL. TLS servers can register an SNICallback function to select a certificate based on the client's requested hostname. When that callback throws synchronously on unexpected input, the exception bypasses Node.js's TLS error-handling paths (tlsClientError and error events) and propagates as an uncaught exception, crashing the Node.js process.
Node.js originally fixed CVE-2026-21637 in January 2026, covering the pskCallback and ALPNCallback options. Its own March 24, 2026 security blog post, titled "Incomplete fix for CVE-2026-21637," states plainly that the January fix was incomplete and extends it to close the same gap in SNICallback, under the same CVE identifier. This entry documents the March 2026 fix, which is what the HeroDevs NES versions below address.
Details
Module Info
- Product: Node.js
- Affected packages: node (the runtime's built-in
tlsmodule, specifically the callback-handling code inlib/_tls_wrap.js) - Affected versions: Per the Node.js security blog (March 24, 2026 release, SNICallback gap): >=20.0.0 before 20.20.2; >=22.0.0 before 22.22.2; >=24.0.0 before 24.14.1; >=25.0.0 before 25.8.2. Per NVD's own CVE-2026-21637 record (published January 20, 2026, pskCallback/ALPNCallback only): >=4.0.0 before 20.20.0; >=22.0.0 before 22.22.0; >=24.0.0 before 24.13.0; >=25.0.0 before 25.3.0.
- GitHub repository: https://github.com/nodejs/node
- Published packages: https://nodejs.org/en/download
- Package manager: Not applicable. Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package.
- Fixed in: NES for Node.js v12.22.16 (April 2, 2026), v14.21.10 (April 1, 2026), v16.20.11 (April 3, 2026), v18.20.16 (March 30, 2026); upstream Node.js 20.20.2, 22.22.2, 24.14.1, 25.8.2
Vulnerability Info
This High-severity vulnerability (CVSS v3.1 7.5) is found in Node.js's built-in TLS implementation, specifically the callback-wrapping code in lib/_tls_wrap.js, in every currently-maintained Node.js release line.
TLS servers commonly supply an SNICallback option so the server can select a certificate/security context based on the client's requested hostname (Server Name Indication). Node.js wraps calls into user-supplied TLS callbacks so that most errors surface as ordinary tlsClientError or error events on the server, rather than crashing the whole process.
The flaw is that this wrapping was incomplete for SNICallback: a synchronous throw from inside that callback (for example, when handed an unexpected or malformed servername) is not caught by Node.js's TLS error-handling path and instead propagates as an uncaught exception, crashing the process. A companion class of this bug in the pskCallback and ALPNCallback options was fixed earlier, in January 2026; the March 2026 release closes the same gap for SNICallback.
Note: Only TLS servers that supply a custom SNICallback option are affected. Servers that do not set this option are not impacted.
Mitigation
The Node.js 12.x, 14.x, 16.x, 18.x, and 20.x release lines are past their support window and will not receive further upstream updates. Node.js 12.x reached End-of-Life on April 30, 2022, Node.js 14.x on April 30, 2023, Node.js 16.x on September 11, 2023, Node.js 18.x on April 30, 2025, and Node.js 20.x on April 30, 2026. For more information see here.
Users of the affected components should apply one of the following mitigations:
- Upgrade to a supported Node.js LTS release, 22.x at 22.22.2 or later, or 24.x at 24.14.1 or later, that contains the fix.
- Migrate affected applications away from the End-of-Life Node.js release lines.
- Leverage a commercial support partner like HeroDevs for post-EOL security support, through NES for Node.js.
Credits
- mbarbs (reporter)
- mcollina (remediation developer)