Skip to main content
CRITICAL

CVE-2021-22931

CVSS v3

9.8

CRITICAL

EPSS Score

22.0 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

Technical details

Published
2021-08-16

Frequently asked questions

What is CVE-2021-22931?

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

Is CVE-2021-22931 actively exploited?

Active exploitation of CVE-2021-22931 has not been confirmed. Its EPSS score was 22.0% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-22931?

CVE-2021-22931 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-22931 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key