If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.
Conclusion & alert: CVE-2021-22939 is rated High Exploit Risk (74.9/100): CVSS Medium severity, with high exploitation likelihood (EPSS 14.73%, 96th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +14.60% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.13% | 14.73% | +14.60% |
| 2 | 2025-11-21 | 2.63% | 0.13% | -2.49% |
| 3 | 2025-11-18 | — | 2.63% | — |
Full EPSS history (39 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2021-22939: 2 source package rows (nodejs, nodejs-current); 63 state rows across 16 repos (3.11-main, 3.12-main, 3.17-community, 3.17-main, 3.18-community, 3.18-main, 3.19-community, 3.19-main, 3.20-community, 3.20-main, 3.21-community, 3.21-main, 3.22-community, 3.22-main, edge-community, edge-main); fixed 16, open 47. | https://security.alpinelinux.org/vuln/CVE-2021-22939 |
debian
|
not yet assigned | CVE-2021-22939 not yet assigned priority: Debian including 1 source packages (nodejs), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-22939 |
gentoo
|
low | CVE-2021-22939: 2 GLSA(s) (202401-02, 202405-29), 2 atom(s) (net-dns/c-ares, net-libs/nodejs); latest impact low. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2021-22939 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2021-22939 |
suse
|
medium | CVE-2021-22939 severity moderate: SUSE including 67 source package names (12:nodejs12-12.22.5-4.19.1, 12:npm12-12.22.5-4.19.1, …), 189 product×package rows across 35 product lines (Container bci/node, Container bci/nodejs, … (35 product lines)): Fixed 123, Known Not Affected 66. | https://www.suse.com/security/cve/CVE-2021-22939/ |
ubuntu
|
low | CVE-2021-22939 low priority: Ubuntu including 1 source packages (nodejs), 15 status rows across 15 suites (bionic, focal, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 8, ignored 3, needed 3, released 1. | https://ubuntu.com/security/CVE-2021-22939 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| nodejs | node.js | >= 12.0.0, < 12.22.5 | cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* |
| nodejs | node.js | >= 14.0.0, < 14.17.5 | cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* |
| nodejs | node.js | >= 16.0.0, < 16.6.2 | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
| oracle | graalvm | 20.3.3 | cpe:2.3:a:oracle:graalvm:20.3.3:*:*:*:enterprise:*:*:* |
| oracle | graalvm | 21.2.0 | cpe:2.3:a:oracle:graalvm:21.2.0:*:*:*:enterprise:*:*:* |
| oracle | jd_edwards_enterpriseone_tools | <= 9.2.6.1 | cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:* |
| oracle | mysql_cluster | <= 8.0.26 | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.57 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.58 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.59 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:* |
| netapp | nextgen_api | — | cpe:2.3:a:netapp:nextgen_api:-:*:*:*:*:*:*:* |
| siemens | sinec_infrastructure_network_services | < 1.0.1.1 | cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | Patch Third Party Advisory |
| https://hackerone.com/reports/1278254 | Exploit Issue Tracking Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/10/msg00006.html | Issue Tracking Third Party Advisory |
| https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases/ | Patch Vendor Advisory |
| https://security.gentoo.org/glsa/202401-02 | |
| https://security.netapp.com/advisory/ntap-20210917-0003/ | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujan2022.html | Patch Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujul2022.html | Patch Third Party Advisory |
| https://www.oracle.com/security-alerts/cpuoct2021.html | Patch Third Party Advisory |