How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

HTTPS certificate non-validation vulnerability in Node.js

calendar_today August 11, 2021 domain http-toolkit

Today Node.js announced and released a security fix for CVE-2021-22939 , along with two other high severity issues. They’ve rated this vulnerability as ‘low severity’, but I think it’s worth a closer look, as (imo) this really understates the risk here, and the potentially widespread impact. In practice, this poses a risk to anybody making TLS connections from Node.js, e.g.

open_in_new Read original post