CVE-2016-6303: Node.js

Critical severity, CVSS 9.8. EPSS: 32% chance of exploitation in the next 30 days.

Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.

Affected products

  • Node.js Node.js: before 0.12.16 (fixed in 0.12.16); from 4.0.0, before 4.6.0 (fixed in 4.6.0); from 6.0.0, before 6.6.0 (fixed in 6.6.0)
  • OpenSSL OpenSSL: version 1.0.1 only; version 1.0.1a only; version 1.0.1b only; version 1.0.1c only; version 1.0.1d only; version 1.0.1e only; …

Published 2016-09-16. Last modified 2026-06-17.