CVE-2017-15896: Node.js

Critical severity, CVSS 9.1. EPSS: 2.4% chance of exploitation in the next 30 days.

Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.

Affected products

  • Node.js Node.js: from 4.0.0, up to and including 4.1.2; from 4.2.0, before 4.8.7 (fixed in 4.8.7); from 6.0.0, up to and including 6.8.1; from 6.9.0, before 6.12.2 (fixed in 6.12.2); from 8.0.0, up to and including 8.8.1; from 8.9.0, before 8.9.3 (fixed in 8.9.3); …

Published 2017-12-11. Last modified 2026-06-17.