node/test
Filip Skokan 98fbc89211
crypto: guard WebCrypto cipher output length
Reject WebCrypto cipher operations whose computed output length would
exceed INT_MAX before passing the length to OpenSSL.

This avoids signed overflow in the AES and ChaCha20-Poly1305 one-shot
cipher paths and turns oversized inputs into a clean operation failure.

Refs: https://hackerone.com/reports/3760016
Signed-off-by: Filip Skokan <panva.ip@gmail.com>
PR-URL: https://github.com/nodejs-private/node-private/pull/878
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
CVE-ID: CVE-2026-48933
2026-06-17 18:52:23 +02:00
..
abort
addons
async-hooks test: deflake async-hooks statwatcher test 2026-05-27 11:35:46 +02:00
benchmark
cctest crypto: guard WebCrypto cipher output length 2026-06-17 18:52:23 +02:00
client-proxy lib,test: redact proxy credentials in tunnel errors 2026-06-17 18:50:12 +02:00
common debugger,test: deflake resume failure test and add debug logs 2026-05-27 11:35:49 +02:00
doctool
embedding
es-module
ffi ffi: validate 'void' as parameter type in getFunction and getFunctions 2026-05-27 11:35:50 +02:00
fixtures test_runner: ignore erased TS lines in coverage 2026-05-30 19:26:25 +02:00
fuzzers
internet
js-native-api
known_issues
message
module-hooks
node-api
nop
overlapped-checker
parallel http: fix response queue poisoning in http.Agent 2026-06-17 18:52:20 +02:00
pseudo-tty
pummel
report
sea
sequential
sqlite
system-ca
test-runner
test426 test: update test426-fixtures to 9b9e225b5a63139e9a95cdd1bf874a8f0b9d131 2026-05-27 11:35:48 +02:00
testpy
tick-processor
tools
v8-updates
wasi
wasm-allocation
wpt
eslint.config_partial.mjs tools: add lint rule for aborted AbortController 2026-05-30 19:26:26 +02:00
README.md
root.status

Node.js Core Tests

This directory contains code and data used to test the Node.js implementation.

For a detailed guide on how to write tests in this directory, see the guide on writing tests.

On how to run tests in this directory, see the contributing guide.

For the tests to run on Windows, be sure to clone Node.js source code with the autocrlf git config flag set to true.

Test Directories

Directory Runs on CI Purpose
abort Yes Tests that use --abort-on-uncaught-exception and other cases where we want to avoid generating a core file.
addons Yes Tests for addon functionality along with some tests that require an addon.
async-hooks Yes Tests for async_hooks functionality.
benchmark Yes Test minimal functionality of benchmarks.
cctest Yes C++ tests that are run as part of the build process.
code-cache No Tests for a Node.js binary compiled with V8 code cache.
common N/A Common modules shared among many tests.1
doctool Yes Tests for the documentation generator.
es-module Yes Test ESM module loading.
fixtures N/A Test fixtures used in various tests throughout the test suite.
internet No Tests that make real outbound network connections.2
js-native-api Yes Tests for Node.js-agnostic Node-API functionality.
known_issues Yes Tests reproducing known issues within the system.3
message Yes Tests for messages that are output for various conditions
node-api Yes Tests for Node.js-specific Node-API functionality.
parallel Yes Various tests that are able to be run in parallel.
pseudo-tty Yes Tests that require stdin/stdout/stderr to be a TTY.
pummel No Various tests for various modules / system functionality operating under load.
sequential Yes Various tests that must not run in parallel.
testpy N/A Test configuration utility used by various test suites.
tick-processor No Tests for the V8 tick processor integration.4
v8-updates No Tests for V8 performance integration.

  1. Documentation ↩︎

  2. Tests for networking related modules may also be present in other directories, but those tests do not make outbound connections. ↩︎

  3. All tests inside of this directory are expected to fail. If a test doesn't fail on certain platforms, those should be skipped via known_issues.status. ↩︎

  4. The tests are for the logic in lib/internal/main/prof_process.js and lib/internal/v8_prof_polyfill.js. The tests confirm that the profile processor packages the correct set of scripts from V8 and introduces the correct platform specific logic. ↩︎