PT-2025-21253 · Node.Js+8 · Node.Js+8
Panva
+1
·
Published
2025-01-01
·
Updated
2025-12-08
·
CVE-2025-23166
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Node.js versions 20.x through 24.x
Description
Node.js is susceptible to a remote crash issue due to a flaw in the
SignTraits::DeriveBits() function. This flaw can be triggered by malformed crypto input in background threads, leading to a denial-of-service condition. The issue arises from an incorrect call to ThrowException() based on user-supplied inputs. Approximately 17 million systems are potentially affected.Recommendations
Update Node.js to the latest version to address this issue.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Debian
Node.Js
Red Hat
Red Os
Rocky Linux
Suse