{"id":"CVE-2021-44533","title":"Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly","summary":"Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be inter…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-295","CWE-295"],"vendor":"nodejs","product":"node.js","affected":["node.js < 12.22.9","node.js >= 14.0.0, < 14.18.3","node.js >= 16.0.0, < 16.13.2","node.js >= 17.0.0, < 17.3.1","graalvm = 20.3.5","graalvm = 21.3.1","graalvm = 22.0.0.2","mysql_cluster < 8.0.29","mysql_cluster = 8.0.29","mysql_connectors <= 8.0.28","mysql_enterprise_monitor <= 8.0.29","mysql_server <= 5.7.37","mysql_server >= 8.0.0, <= 8.0.28","mysql_workbench <= 8.0.28","peoplesoft_enterprise_peopletools = 8.58","peoplesoft_enterprise_peopletools = 8.59","debian_linux = 11.0"],"patched":["node.js 17.3.1","mysql_cluster 8.0.29"],"published":"2022-02-24","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:13.950","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-44533","references":[{"url":"https://hackerone.com/reports/1429694","label":"support@hackerone.com"},{"url":"https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/","label":"support@hackerone.com"},{"url":"https://security.netapp.com/advisory/ntap-20220325-0007/","label":"support@hackerone.com"},{"url":"https://www.debian.org/security/2022/dsa-5170","label":"support@hackerone.com"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"support@hackerone.com"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"support@hackerone.com"},{"url":"https://hackerone.com/reports/1429694","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20220325-0007/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2022/dsa-5170","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.09358,"epssPercentile":0.95275,"ingestedAt":"2026-10-08T23:16:47.333Z","slug":"CVE-2021-44533","body":"## Overview\n\nNode.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.\n\n## Affected\n\n- `node.js < 12.22.9`\n- `node.js >= 14.0.0, < 14.18.3`\n- `node.js >= 16.0.0, < 16.13.2`\n- `node.js >= 17.0.0, < 17.3.1`\n- `graalvm = 20.3.5`\n- `graalvm = 21.3.1`\n- `graalvm = 22.0.0.2`\n- `mysql_cluster < 8.0.29`\n- `mysql_cluster = 8.0.29`\n- `mysql_connectors <= 8.0.28`\n- `mysql_enterprise_monitor <= 8.0.29`\n- `mysql_server <= 5.7.37`\n- `mysql_server >= 8.0.0, <= 8.0.28`\n- `mysql_workbench <= 8.0.28`\n- `peoplesoft_enterprise_peopletools = 8.58`\n- `peoplesoft_enterprise_peopletools = 8.59`\n- `debian_linux = 11.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `node.js 17.3.1`\n- `mysql_cluster 8.0.29`","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":29.2,"likelihood":1.9,"exploitation":0,"ransomware":0},"changes":[]}