Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HNetapp Active Iq Unified Manager
APPNetappall versionsNetapp Nextgen Api
APPNetappall versionsNetapp Oncommand Insight
APPNetappall versionsNetapp Oncommand Workflow Automation
APPNetappall versionsNetapp Snapcenter
APPNetappall versionsNode.js
APPNodejs12.0.0 – 12.12.012.13.0 – 12.22.5 (excl.)14.0.0 – 14.14.014.15.0 – 14.17.5 (excl.)16.0.0 – 16.6.2 (excl.)Oracle Graalvm
APPOracle20.3.321.2.0Oracle MySQL Cluster
APPOracle≤ 8.0.26Oracle Peoplesoft Enterprise Peopletools
APPOracle8.578.588.59Siemens Sinec Infrastructure Network Services
APPSiemens< 1.0.1.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEXSS
References
Related vulnerabilities
CVE-2026-35273CRITICAL9.8⚠ KEVPL ✓same product
Pominięcie uwierzytelnienia w Oracle PeopleSoft PeopleTools (RCE/Takeover)
CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
CVE-2019-2725CRITICAL9.8⚠ KEVPL ✓same product
RCE w Oracle WebLogic Server — przejęcie serwera bez uwierzytelnienia
CVE-2016-8735CRITICAL9.8⚠ KEVPL ✓same product
Apache Tomcat RCE przez JmxRemoteLifecycleListener (JMX)
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX