---
id: CVE-2021-44533
title: >-
  Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle
  multi-value Relative Distinguished Names correctly
summary: >-
  Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle
  multi-value Relative Distinguished Names correctly. Attackers could craft
  certificate subjects containing a single-value Relative Distinguished Name
  that would be inter…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-295
vendor: nodejs
product: node.js
affected:
  - node.js < 12.22.9
  - 'node.js >= 14.0.0, < 14.18.3'
  - 'node.js >= 16.0.0, < 16.13.2'
  - 'node.js >= 17.0.0, < 17.3.1'
  - graalvm = 20.3.5
  - graalvm = 21.3.1
  - graalvm = 22.0.0.2
  - mysql_cluster < 8.0.29
  - mysql_cluster = 8.0.29
  - mysql_connectors <= 8.0.28
  - mysql_enterprise_monitor <= 8.0.29
  - mysql_server <= 5.7.37
  - 'mysql_server >= 8.0.0, <= 8.0.28'
  - mysql_workbench <= 8.0.28
  - peoplesoft_enterprise_peopletools = 8.58
  - peoplesoft_enterprise_peopletools = 8.59
  - debian_linux = 11.0
patched:
  - node.js 17.3.1
  - mysql_cluster 8.0.29
published: '2022-02-24'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:13.950'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-44533'
references:
  - url: 'https://hackerone.com/reports/1429694'
    label: support@hackerone.com
  - url: 'https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/'
    label: support@hackerone.com
  - url: 'https://security.netapp.com/advisory/ntap-20220325-0007/'
    label: support@hackerone.com
  - url: 'https://www.debian.org/security/2022/dsa-5170'
    label: support@hackerone.com
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: support@hackerone.com
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: support@hackerone.com
  - url: 'https://hackerone.com/reports/1429694'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220325-0007/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2022/dsa-5170'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-44533.json
  - url: 'https://access.redhat.com/security/cve/CVE-2021-44533'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2040856'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2021-44533'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-44533'
  - url: 'https://access.redhat.com/errata/RHSA-2022:4914'
  - url: 'https://access.redhat.com/errata/RHSA-2022:7044'
  - url: 'https://access.redhat.com/errata/RHSA-2023:3742'
  - url: 'https://access.redhat.com/errata/RHEA-2022:4925'
  - url: 'https://access.redhat.com/errata/RHEA-2022:5221'
  - url: 'https://access.redhat.com/errata/RHEA-2022:5615'
  - url: 'https://access.redhat.com/errata/RHSA-2023:1742'
  - url: 'https://access.redhat.com/errata/RHEA-2022:5139'
  - url: 'https://access.redhat.com/errata/RHSA-2022:7830'
  - url: 'https://access.redhat.com/errata/RHSA-2022:9073'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - score-dispute
epss: 0.09358
epssPercentile: 0.95275
ingestedAt: '2026-10-08T23:16:47.333Z'
scores:
  nvd: 5.3
  vendor: 7.4
---

## Overview

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.

## Affected

- `node.js < 12.22.9`
- `node.js >= 14.0.0, < 14.18.3`
- `node.js >= 16.0.0, < 16.13.2`
- `node.js >= 17.0.0, < 17.3.1`
- `graalvm = 20.3.5`
- `graalvm = 21.3.1`
- `graalvm = 22.0.0.2`
- `mysql_cluster < 8.0.29`
- `mysql_cluster = 8.0.29`
- `mysql_connectors <= 8.0.28`
- `mysql_enterprise_monitor <= 8.0.29`
- `mysql_server <= 5.7.37`
- `mysql_server >= 8.0.0, <= 8.0.28`
- `mysql_workbench <= 8.0.28`
- `peoplesoft_enterprise_peopletools = 8.58`
- `peoplesoft_enterprise_peopletools = 8.59`
- `debian_linux = 11.0`

## Remediation

Upgrade past the affected range:

- `node.js 17.3.1`
- `mysql_cluster 8.0.29`

## Vendor advisories

- **RHSA-2022:4914** · Red Hat · fixed in: Red Hat Software Collections for RHEL Workstation(v. 7), Red Hat Software Collections for RHEL(v. 7) · released 2022-06-06 · [advisory](https://access.redhat.com/errata/RHSA-2022:4914)
- **RHSA-2022:7044** · Red Hat · fixed in: Red Hat Software Collections for RHEL Workstation(v. 7), Red Hat Software Collections for RHEL(v. 7) · released 2022-10-19 · [advisory](https://access.redhat.com/errata/RHSA-2022:7044)
- **RHSA-2023:3742** · Red Hat · fixed in: RHODF 4.13 for RHEL 9 · released 2023-06-21 · [advisory](https://access.redhat.com/errata/RHSA-2023:3742)
- **RHEA-2022:4925** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v. 8.1) · released 2022-06-07 · [advisory](https://access.redhat.com/errata/RHEA-2022:4925)
- **RHEA-2022:5221** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 8.2) · released 2022-06-28 · [advisory](https://access.redhat.com/errata/RHEA-2022:5221)
- **RHEA-2022:5615** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.8.4) · released 2022-07-19 · [advisory](https://access.redhat.com/errata/RHEA-2022:5615)
- **RHSA-2023:1742** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.8.6) · released 2023-04-12 · [advisory](https://access.redhat.com/errata/RHSA-2023:1742)
- **RHEA-2022:5139** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2022-06-21 · [advisory](https://access.redhat.com/errata/RHEA-2022:5139)
- **RHSA-2022:7830** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2022-11-08 · [advisory](https://access.redhat.com/errata/RHSA-2022:7830)
- **RHSA-2022:9073** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2022-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2022:9073)
- **Red Hat VEX** · Moderate · affected: Red Hat Quay 3 · no fix planned: Red Hat Quay 3 · updated 2026-10-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-44533.json)
