CVE-2016-7052: Node.js
High severity, CVSS 7.5. EPSS: 29.5% chance of exploitation in the next 30 days.
crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.
Affected products
- Node.js Node.js: from 4.0.0, up to and including 4.1.2; from 4.2.0, before 4.6.0 (fixed in 4.6.0); from 6.0.0, before 6.7.0 (fixed in 6.7.0)
- Novell Suse Linux Enterprise Module For Web Scripting: version 12.0 only
- OpenSSL OpenSSL: version 1.0.2i only
Published 2016-09-26. Last modified 2026-06-17.