CVE-2020-8172: Node.js

High severity, CVSS 7.4. EPSS: 6.1% chance of exploitation in the next 30 days.

TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.

Affected products

  • Node.js Node.js: from 12.0.0, before 12.18.0 (fixed in 12.18.0); from 14.0.0, before 14.4.0 (fixed in 14.4.0)
  • Oracle Banking Extensibility Workbench: version 14.3.0 only; version 14.4.0 only
  • Oracle Blockchain Platform: before 21.1.2 (fixed in 21.1.2)
  • Oracle Graalvm: version 19.3.2 only; version 20.1.0 only
  • Oracle MySQL Cluster: up to and including 7.3.30; from 7.4.0, up to and including 7.4.29; from 7.5.0, up to and including 7.5.19; from 7.6.0, up to and including 7.6.15; from 8.0.0, up to and including 8.0.21

Published 2020-06-08. Last modified 2026-06-17.