{"id":"CVE-2022-31183","aliases":["GHSA-2cpx-6pqp-wf35"],"url":"https://o3.security/vulnerability/CVE-2022-31183","summary":"mTLS client verification is skipped in fs2 on Node.js","details":"### Impact\n\nWhen establishing a server-mode `TLSSocket` using `fs2-io` on Node.js, the parameter `requestCert = true` is ignored, peer certificate verification is skipped, and the connection proceeds.\n\nThe vulnerability is limited to:\n1. `fs2-io` running on Node.js. The JVM TLS implementation is completely independent.\n2. `TLSSocket`s in server-mode. Client-mode `TLSSocket`s are implemented via a different API.\n3. mTLS as enabled via `requestCert = true` in `TLSParameters`. The default setting is `false` for server-mode `TLSSocket`s.\n\nIt was introduced with the initial Node.js implementation of fs2-io in v3.1.0.\n\n### Patches\n\nA patch is released in v3.2.11. The `requestCert = true` parameter is respected and the peer certificate is verified. If verification fails, a `SSLException` is raised.\n\n### Workarounds\n\nIf using an unpatched version on Node.js, do not use a server-mode `TLSSocket` with `requestCert = true` to establish a mTLS connection.\n\n### References\n- https://github.com/nodejs/node/issues/43994\n- https://www.cloudflare.com/learning/access-management/what-is-mutual-tls/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* [Open an issue.](https://github.com/typelevel/fs2/issues/new/choose)\n* Contact the [Typelevel Security Team](https://github.com/typelevel/.github/blob/main/SECURITY.md).","published":"2022-08-01T19:50:11Z","modified":"2026-08-12T03:51:45.573339052Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"co.fs2:fs2-io","fixedVersion":"3.2.11"},{"ecosystem":"Maven","name":"co.fs2:fs2-io_2.12","fixedVersion":"3.2.11"},{"ecosystem":"Maven","name":"co.fs2:fs2-io_3","fixedVersion":"3.2.11"},{"ecosystem":"Maven","name":"co.fs2:fs2-io_2.13","fixedVersion":"3.2.11"},{"ecosystem":"Maven","name":"co.fs2:fs2-io_sjs1_2.13","fixedVersion":"3.2.11"},{"ecosystem":"Maven","name":"co.fs2:fs2-io_sjs1_3","fixedVersion":"3.2.11"}],"fix":{"url":"https://github.com/typelevel/fs2/commit/659824395826a314e0a4331535dbf1ef8bef8207","label":"typelevel/fs2@6598243"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31183.json"},{"type":"ADVISORY","url":"https://github.com/typelevel/fs2/security/advisories/GHSA-2cpx-6pqp-wf35"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31183"},{"type":"REPORT","url":"https://github.com/nodejs/node/issues/43994"},{"type":"FIX","url":"https://github.com/typelevel/fs2/commit/659824395826a314e0a4331535dbf1ef8bef8207"},{"type":"WEB","url":"https://github.com/typelevel/fs2/commit/19ce392e8093d9571387dbd78e159e655a85aeea"},{"type":"PACKAGE","url":"https://github.com/typelevel/fs2"},{"type":"WEB","url":"https://github.com/typelevel/fs2/releases/tag/v3.2.11"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:45.573339052Z"}}