CVE-2021-22884: Node.Js Vulnerability (CVSS 7.5) — Fix & Details

CVE-2021-22884 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes "localhost6". When "localhost6" is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. EPSS estimates a 32.36% chance of exploitation in the next 30 days.

Description

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes "localhost6". When "localhost6" is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the "localhost6" domain. As long as the attacker uses the "localhost6" domain, they can still apply the attack described in CVE-2018-7160.

Metrics

CVSS 3.17.5/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability 32.36% 98.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Vendor Product Versions
Nodejs Node.Js >= 10.0.0, < 10.24.0
Nodejs Node.Js >= 12.0.0, < 12.21.0
Nodejs Node.Js >= 14.0.0, < 14.16.0
Nodejs Node.Js >= 15.0.0, < 15.10.0
Fedoraproject Fedora 32
Fedoraproject Fedora 33
Fedoraproject Fedora 34
Netapp Active Iq Unified Manager All versions
Netapp E-Series Performance Analyzer All versions
Netapp Oncommand Insight All versions
Netapp Oncommand Workflow Automation All versions
Netapp Snapcenter All versions
Oracle Graalvm 19.3.5
Oracle Graalvm 20.3.1.2
Oracle Graalvm 21.0.0.2
Oracle Jd Edwards Enterpriseone Tools < 9.2.6.0
Oracle Mysql Cluster <= 8.0.25
Oracle Nosql Database < 20.3
Oracle Peoplesoft Enterprise Peopletools 8.58
Oracle Peoplesoft Enterprise Peopletools 8.59
Siemens Sinec Infrastructure Network Services < 1.0.1.1

References

Timeline

Published Mar 3, 2021

Last Modified Jun 17, 2026

Status Modified

Frequently Asked Questions

What is CVE-2021-22884? Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes "localhost6". When "localhost6" is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the "localhost6" domain.

How severe is CVE-2021-22884? CVE-2021-22884 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 32.36% probability of exploitation in the next 30 days.

How do I fix CVE-2021-22884? Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.