PT-2025-29694 · Node.Js · Node.Js

Sharp_Edged

·

Published

2025-07-15

·

Updated

2025-07-22

·

CVE-2025-27209

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Node.js versions 24.0.0 and later
Description The V8 release in Node.js reintroduced a HashDoS vulnerability due to changes in string hash computation using rapidhash. An attacker controlling the strings to be hashed can generate numerous hash collisions, even without knowing the hash seed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2025-09382
BDU:2025-09383
BIT-NODE-2025-27209
BIT-NODE-MIN-2025-27209
CVE-2025-27209

Affected Products

Node.Js