A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:1843 https://access.redhat.com/errata/RHSA-2026:1843
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:1842 https://access.redhat.com/errata/RHSA-2026:1842
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:2422 https://access.redhat.com/errata/RHSA-2026:2422
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:2421 https://access.redhat.com/errata/RHSA-2026:2421
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:2420 https://access.redhat.com/errata/RHSA-2026:2420
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:2781 https://access.redhat.com/errata/RHSA-2026:2781
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:2782 https://access.redhat.com/errata/RHSA-2026:2782
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:2783 https://access.redhat.com/errata/RHSA-2026:2783
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:7350 https://access.redhat.com/errata/RHSA-2026:7350
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:7675 https://access.redhat.com/errata/RHSA-2026:7675
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:7670 https://access.redhat.com/errata/RHSA-2026:7670