CVE-2017-3731: Node.js
High severity, CVSS 7.5. EPSS: 57.3% chance of exploitation in the next 30 days.
If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.
Affected products
- Node.js Node.js: from 4.0.0, up to and including 4.1.2; from 4.2.0, before 4.7.3 (fixed in 4.7.3); from 5.0.0, up to and including 5.12.0; from 6.0.0, up to and including 6.8.1; from 6.9.0, before 6.9.5 (fixed in 6.9.5); from 7.0.0, before 7.5.0 (fixed in 7.5.0)
- OpenSSL OpenSSL: version 1.1.0a only; version 1.1.0b only; version 1.1.0c only; version 1.0.2 only; version 1.0.2a only; version 1.0.2b only; …
Published 2017-05-04. Last modified 2026-06-17.