Back

HIGH

nodejs: DNS rebinding in inspect via invalid octal IP address

Published Dec 5, 2022

Description

A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.

Affected products

Remediation

Red Hat statement

Redhat has marked this vulnerability as moderate for two primary reasons. 1. The vulnerable inspect functionality might not be enabled, exposed, or reachable in many deployments. 2.The code path might require very specific configurations or conditions (e.g. DNS rebinding, certain host/IP setups) that are rare in default environments.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Dec 5, 2022
Updated Apr 30, 2025
Reserved Oct 20, 2022
CISA Vulnrichment
Updated Apr 24, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 4, 2022
ENISA EUVD
Assigner hackerone
Published Dec 5, 2022
Updated Apr 30, 2025
Exploited since n/a
EUVD-2022-46545