PT-2017-14274 · Node.Js+2 · Node.Js+2

David Benjamin

+1

·

Published

2017-12-11

·

Updated

2026-05-18

·

CVE-2017-15896

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Node.js (affected versions not specified)
Description The issue concerns a TLS handshake failure due to the use of SSL read(), allowing an active network attacker to send application data to Node.js using the TLS or HTTP2 modules, bypassing TLS authentication and encryption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2018-1303
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2017-15896
SUSE-SU-2018:0002-1
SUSE-SU-2018:0293-1
SUSE-SU-2019:14246-1
SUSE-SU-2019_14246-1

Affected Products

Alt Linux
Node.Js
Suse