CVE-2026-21637 HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers

User avatar
admin Verified Great Britain
Site Admin
Posts: 25972
Joined: Wed Jun 11, 2025 9:20 pm

Awards

CVE-2026-21637 HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers

Post by admin Verified »

[CVE-2026-21637](https://www.cve.org/CVERecord?id=CVE-2026-21637) is regarding a vulnerability in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when pskCallback or ALPNCallback are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. HackerOne created this CVE on their behalf. The documented Visual Studio updates incorporate updates in Node.js which address this vulnerability. Please see [CVE-2026-21637](https://www.cve.org/CVERecord?id=CVE-2026-21637) for more information.

Source: https://msrc.microsoft.com/update-guide ... 2026-21637
Post Reply

Who is online

Users browsing this forum: No registered users and 0 guests