In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade nodejs/node to version 20.20.2, 22.22.2, 24.14.1, 25.8.2 or higher.
Affected versions of this package are vulnerable to Uncaught Exception in the TLS module when a SNICallback throws synchronously on unexpected input the exception bypasses TLS error handlers and propagates as an uncaught exception. A remote attacker can crash or exhaust resources of a TLS server by sending input that causes the callback to throw an error.
Note:
This is caused by an incomplete fix for CVE-2026-21637.