Wrap pskCallback and ALPNCallback invocations in try-catch blocks to route exceptions through owner.destroy() instead of letting them become uncaught exceptions. This prevents remote attackers from crashing TLS servers or causing resource exhaustion. Fixes: https://hackerone.com/reports/3473882 PR-URL: https://github.com/nodejs-private/node-private/pull/782 Backport-PR-URL: https://github.com/nodejs/node/pull/61044 CVE-ID: CVE-2026-21637 Refs: https://github.com/nodejs/node/pull/57643 |
||
|---|---|---|
| .. | ||
| assert | ||
| async_local_storage | ||
| bootstrap | ||
| child_process | ||
| cluster | ||
| console | ||
| crypto | ||
| debugger | ||
| dns | ||
| encoding | ||
| errors | ||
| events | ||
| fs | ||
| http2 | ||
| inspector | ||
| legacy | ||
| main | ||
| modules | ||
| per_context | ||
| perf | ||
| process | ||
| quic | ||
| readline | ||
| repl | ||
| source_map | ||
| streams | ||
| test | ||
| test_runner | ||
| tls | ||
| util | ||
| v8 | ||
| vm | ||
| watch_mode | ||
| webstreams | ||
| worker | ||
| abort_controller.js | ||
| assert.js | ||
| async_context_frame.js | ||
| async_hooks.js | ||
| blob.js | ||
| blocklist.js | ||
| buffer.js | ||
| child_process.js | ||
| cli_table.js | ||
| constants.js | ||
| data_url.js | ||
| dgram.js | ||
| encoding.js | ||
| error_serdes.js | ||
| errors.js | ||
| event_target.js | ||
| file.js | ||
| fixed_queue.js | ||
| freelist.js | ||
| freeze_intrinsics.js | ||
| heap_utils.js | ||
| histogram.js | ||
| http.js | ||
| inspector_async_hook.js | ||
| inspector_network_tracking.js | ||
| js_stream_socket.js | ||
| linkedlist.js | ||
| locks.js | ||
| mime.js | ||
| navigator.js | ||
| net.js | ||
| options.js | ||
| priority_queue.js | ||
| promise_hooks.js | ||
| querystring.js | ||
| README.md | ||
| repl.js | ||
| socket_list.js | ||
| socketaddress.js | ||
| stream_base_commons.js | ||
| timers.js | ||
| trace_events_async_hooks.js | ||
| tty.js | ||
| url.js | ||
| util.js | ||
| v8_prof_polyfill.js | ||
| v8_prof_processor.js | ||
| validators.js | ||
| vm.js | ||
| wasm_web_api.js | ||
| watchdog.js | ||
| webidl.js | ||
| webstorage.js | ||
| worker.js | ||
Internal Modules
The modules located in lib/internal directory are exclusively meant
for internal usage within the Node.js core. They are not intended to
be accessed via user modules require(). These modules may change at
any point in time. Relying on these internal modules outside the core
is not supported and can lead to unpredictable behavior.
In certain scenarios, accessing these internal modules for debugging or
experimental purposes might be necessary. Node.js provides the --expose-internals
flag to expose these modules to userland code. This flag only exists to
assist Node.js maintainers with debugging internals. It is not meant for
use outside the project.