{"id":"CVE-2022-31183","aliases":["GHSA-2cpx-6pqp-wf35"],"url":"https://o3.security/vulnerability/CVE-2022-31183","summary":"mTLS client verification is skipped in fs2 on Node.js","details":"fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on Node.js, the parameter `requestCert = true` is ignored, peer certificate verification is skipped, and the connection proceeds. The vulnerability is limited to: 1. `fs2-io` running on Node.js. The JVM TLS implementation is completely independent. 2. `TLSSocket`s in server-mode. Client-mode `TLSSocket`s are implemented via a different API. 3. mTLS as enabled via `requestCert = true` in `TLSParameters`. The default setting is `false` for server-mode `TLSSocket`s. It was introduced with the initial Node.js implementation of fs2-io in 3.1.0. A patch is released in v3.2.11. The requestCert = true parameter is respected and the peer certificate is verified. If verification fails, a SSLException is raised. If using an unpatched version on Node.js, do not use a server-mode TLSSocket with requestCert = true to establish a mTLS connection.","published":"2022-08-01T19:50:11Z","modified":"2026-07-15T01:49:08.225866990Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"co.fs2:fs2-io","fixedVersion":"3.2.11"},{"ecosystem":"Maven","name":"co.fs2:fs2-io_2.12","fixedVersion":"3.2.11"},{"ecosystem":"Maven","name":"co.fs2:fs2-io_3","fixedVersion":"3.2.11"},{"ecosystem":"Maven","name":"co.fs2:fs2-io_2.13","fixedVersion":"3.2.11"},{"ecosystem":"Maven","name":"co.fs2:fs2-io_sjs1_2.13","fixedVersion":"3.2.11"},{"ecosystem":"Maven","name":"co.fs2:fs2-io_sjs1_3","fixedVersion":"3.2.11"}],"fix":{"url":"https://github.com/typelevel/fs2/commit/659824395826a314e0a4331535dbf1ef8bef8207","label":"typelevel/fs2@6598243"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31183.json"},{"type":"ADVISORY","url":"https://github.com/typelevel/fs2/security/advisories/GHSA-2cpx-6pqp-wf35"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31183"},{"type":"REPORT","url":"https://github.com/nodejs/node/issues/43994"},{"type":"FIX","url":"https://github.com/typelevel/fs2/commit/659824395826a314e0a4331535dbf1ef8bef8207"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:08.225866990Z"}}