node/lib/internal/tls
Matteo Collina 4bfda307c0
tls: wrap SNICallback invocation in try/catch
Wrap the owner._SNICallback() invocation in loadSNI() with try/catch
to route exceptions through owner.destroy() instead of letting them
become uncaught exceptions. This completes the fix from CVE-2026-21637
which added try/catch protection to callALPNCallback,
onPskServerCallback, and onPskClientCallback but missed loadSNI().

Without this fix, a remote unauthenticated attacker can crash any
Node.js TLS server whose SNICallback may throw on unexpected input
by sending a single TLS ClientHello with a crafted server_name value.

Fixes: https://hackerone.com/reports/3556769
Refs: https://hackerone.com/reports/3473882
CVE-ID: CVE-2026-21637

PR-URL: https://github.com/nodejs-private/node-private/pull/819
Reviewed-By: Robert Nagy <ronagy@icloud.com>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
CVE-ID: CVE-2026-21637
2026-03-20 15:07:12 -03:00
..
common.js tls: avoid external memory leak on invalid protocol versions 2025-10-26 22:30:23 +01:00
secure-context.js tls: add allowPartialTrustChain flag 2024-09-09 17:24:10 +02:00
wrap.js tls: wrap SNICallback invocation in try/catch 2026-03-20 15:07:12 -03:00