Back to vendor advisories
Microsoft Security Response CenterCVE-2026-21637

HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers

CVE-2026-21637 is regarding a vulnerability in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when pskCallback or ALPNCallback are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. HackerOne created this CVE on their behalf. The documented Visual Studio updates incorporate updates in Node.js which address this vulnerability. Please see CVE-2026-21637 for more information.

7.5CVSS out of 10Medium severity
Scope

What the vendor says is affected

  • Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
  • Microsoft Visual Studio 2022 version 17.12
  • Microsoft Visual Studio 2022 version 17.14

Versions the vendor lists as fixed

  • 16.11.55
  • 17.12.19
  • 17.14.30
Next step

What the vendor recommends

Release Notes

Review the complete instructions on the vendor's site
Timeline

When this advisory changed

  1. Published by Microsoft Security Response Center

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

Vulnerabilities

CVEs named in this advisory