Back to blog

// OSSeva Blog

Operations

ERR_OSSL_EVP_UNSUPPORTED in Node.js: Why It Happens and How to Fix It Properly

Matt Reynolds4 min read

The short answer

The ERR_OSSL_EVP_UNSUPPORTED error means your code, or a library it uses, asked OpenSSL for an algorithm or key size that OpenSSL 3.0 no longer allows by default. Node.js 17 was the first release to ship OpenSSL 3.0, and every later version does too. The usual culprit is webpack 4, which hashes modules with MD4, an algorithm that OpenSSL 3 moved into its legacy provider. The error message mentions digital envelope routines:

Error: error:0308010C:digital envelope routines::unsupported
  code: 'ERR_OSSL_EVP_UNSUPPORTED'

The proper fix is to install updated build tooling, which resolves the issue for good. The --openssl-legacy-provider flag is a workaround.

The quick workaround

Node.js added the --openssl-legacy-provider option in Node.js 17 as "a temporary workaround", in the project's own words. It re-enables the legacy provider for one process. Set it as an environment variable in a terminal:

# macOS / Linux
export NODE_OPTIONS=--openssl-legacy-provider
# Windows (PowerShell)
$env:NODE_OPTIONS="--openssl-legacy-provider"

In a Create React App project you can pass it through the script instead: react-scripts --openssl-legacy-provider start. This gets a build running, but it is a stopgap. It turns legacy algorithms back on for everything in the process, and it leaves you on tooling that has not been maintained for years.

The proper fix: update the dependency

  • webpack 5: webpack 5.61.0 switched to a WebAssembly MD4 implementation for Node.js 17 support. Upgrading webpack 5 to a current version is enough.
  • webpack 4: version 4.47.0 added MD4 support for Node.js 18 and later. Loaders and plugins from that era can still call MD4 themselves, so test the build.
  • Create React App: react-scripts 4.0.3 pins webpack 4.44.2, so npm cannot pick up the fix. react-scripts 5 uses webpack 5. The React team deprecated Create React App in February 2025, so moving to Vite or a framework is the durable solution.

Downgrading Node.js to 16 also removes the error, but Node.js 16 reached end of life on 11 September 2023. That trades a build error for a security problem.

The lifecycle problem behind the error

The error usually shows up when a team is forced onto a newer Node.js version because the old one reached end of life. Node.js 18 ended on 30 April 2025. Node.js 20 ended on 30 April 2026, with 20.20.2 as its final release. Node.js 22 LTS ends on 30 April 2027. A project that needs the legacy provider flag is often a project whose front-end toolchain has stalled, and that gets harder with every Node.js release.

If the application cannot move yet, OSSeva keeps end-of-life runtimes patched while the tooling catches up. See Node.js support, and the Node.js 20 and Node.js 18 end-of-life pages.

Frequently asked questions

Can upgrading Node.js fix ERR_OSSL_EVP_UNSUPPORTED?

No. Every Node.js version from 17 onwards uses OpenSSL 3. Update the library that requests the legacy algorithm.

Is the openssl-legacy-provider flag a security risk?

It re-enables weak algorithms such as MD4 for the whole process. For a local build this is a small risk; in a production server it is worth avoiding.

Tags

Node.jsOpenSSLwebpackReactTroubleshooting

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.