CVE-2021-22884 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes "localhost6". When "localhost6" is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. EPSS estimates a 32.36% chance of exploitation in the next 30 days.

## Description

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes "localhost6". When "localhost6" is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the "localhost6" domain. As long as the attacker uses the "localhost6" domain, they can still apply the attack described in CVE-2018-7160.

## Metrics

CVSS 3.17.5/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability 32.36% 98.1th percentile

Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Weakness Enumeration

- [CWE-350](https://cwe.mitre.org/data/definitions/350.html)

## Affected Software

| Vendor        | Product                           | Versions                         |
|---------------|-----------------------------------|----------------------------------|
| Nodejs        | Node.Js                           | >= 10.0.0, < 10.24.0             |
| Nodejs        | Node.Js                           | >= 12.0.0, < 12.21.0             |
| Nodejs        | Node.Js                           | >= 14.0.0, < 14.16.0             |
| Nodejs        | Node.Js                           | >= 15.0.0, < 15.10.0             |
| Fedoraproject | Fedora                            | 32                               |
| Fedoraproject | Fedora                            | 33                               |
| Fedoraproject | Fedora                            | 34                               |
| Netapp        | Active Iq Unified Manager         | All versions                     |
| Netapp        | E-Series Performance Analyzer     | All versions                     |
| Netapp        | Oncommand Insight                 | All versions                     |
| Netapp        | Oncommand Workflow Automation     | All versions                     |
| Netapp        | Snapcenter                        | All versions                     |
| Oracle        | Graalvm                           | 19.3.5                          |
| Oracle        | Graalvm                           | 20.3.1.2                        |
| Oracle        | Graalvm                           | 21.0.0.2                        |
| Oracle        | Jd Edwards Enterpriseone Tools    | < 9.2.6.0                       |
| Oracle        | Mysql Cluster                     | <= 8.0.25                       |
| Oracle        | Nosql Database                    | < 20.3                          |
| Oracle        | Peoplesoft Enterprise Peopletools  | 8.58                            |
| Oracle        | Peoplesoft Enterprise Peopletools  | 8.59                            |
| Siemens       | Sinec Infrastructure Network Services | < 1.0.1.1                     |

## References

- [Siemens Advisory Patch](https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf)
- [HackerOne Report](https://hackerone.com/reports/1069487)
- [Fedora Package Announcements](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4FRS5ZVK4ZQ7XIJQNGIKUXG2DJFHLO7/)
- [Node.js Security Releases](https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/)

## Timeline

Published Mar 3, 2021

Last Modified Jun 17, 2026

Status Modified

## Frequently Asked Questions

**What is CVE-2021-22884?**
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes "localhost6". When "localhost6" is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the "localhost6" domain.

**How severe is CVE-2021-22884?**
CVE-2021-22884 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 32.36% probability of exploitation in the next 30 days.

**How do I fix CVE-2021-22884?**
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.
