Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-23406

31
FAUCET Score

CVE-2021-23406 is a critical vulnerability affecting the pac-resolver package prior to version 5.0.0, stemming from unsafe handling of PAC files when processing untrusted input. This flaw carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness within the cybersecurity community. The fix for this vulnerability is implemented in the node-degenerator library, a dependency maintained by the same developer.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.0.0CPE matchmatch criteria
cpe:2.3:a:pac-resolver_project:pac-resolver:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.86%
Probability of exploitation in next 30 days
EPSS Percentile
85.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0286 is in the 76th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: pac-resolverFixed in: 5.0.0
npmpatch availablevia ghsa
Product: degeneratorFixed in: 3.0.1
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/application-ui-rhel8

Vendor Advisories (2)

npmGHSA-9j49-mfvp-vmhmhigh

Code Injection in pac-resolver

Sep 2, 2021
redhatCVE-2021-23406Important

nodejs-pac-resolver: remote code execution when used with untrusted input due to unsafe PAC file handling

Aug 22, 2021

References

github.com / TooTallNate/node-degenerator/commit/9d25bb67d957bc2e5425fea7bf7a58b3fc64ff9e
PatchThird Party Advisory
github.com / TooTallNate/node-degenerator/commit/ccc3445354135398b6eb1a04c7d27c13b833f2d5
PatchThird Party Advisory
github.com / TooTallNate/node-pac-resolver/releases/tag/5.0.0
PatchRelease NotesThird Party Advisory
snyk.io / vuln/SNYK-JAVA-ORGWEBJARSNPM-1568506
ExploitPatchThird Party Advisory
snyk.io / vuln/SNYK-JS-PACRESOLVER-1564857
ExploitPatchThird Party Advisory