PT-2025-4815 · Nghttp2+10 · Nghttp2+10

Newtmitch

·

Published

2025-01-21

·

Updated

2025-12-08

·

CVE-2025-23085

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Node.js versions 18.x through 23.x
Description A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions.
Recommendations For Node.js versions 18.x, 20.x, 22.x, and 23.x, consider implementing a workaround to handle abrupt socket closures and invalid headers to prevent memory leaks. As a temporary workaround, consider disabling the use of HTTP/2 until a patch is available. Restrict access to the nghttp2 module to minimize the risk of exploitation. Avoid using the nghttp2 library in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:1351
ALSA-2025:1443
ALSA-2025:1446
ALSA-2025:1582
ALSA-2025:1611
ALSA-2025:1613
ALT-PU-2025-1865
AZL-56476
AZL-56519
BDU:2025-02664
BIT-NODE-2025-23085
BIT-NODE-MIN-2025-23085
CESA-2025_1351
CESA-2025_1582
CESA-2025_1611
CVE-2025-23085
DLA-4067-1
ECHO-5E31-886E-C1FC
INFSA-2025_1351
INFSA-2025_1443
INFSA-2025_1446
INFSA-2025_1582
INFSA-2025_1611
INFSA-2025_1613
MGASA-2025-0041
OESA-2025-1090
OESA-2025-1091
OESA-2025-1274
OESA-2025-1275
OESA-2025-1276
OPENSUSE-SU-2025:14706-1
OPENSUSE-SU-2025:15802-1
OPENSUSE-SU-2025_0232-1
OPENSUSE-SU-2025_0233-1
OPENSUSE-SU-2025_0237-1
OPENSUSE-SU-2025_0284-1
RHSA-2025:1351
RHSA-2025:1443
RHSA-2025:1446
RHSA-2025:1582
RHSA-2025:1611
RHSA-2025:1613
RHSA-2025_1351
RHSA-2025_1443
RHSA-2025_1446
RHSA-2025_1582
RHSA-2025_1611
RHSA-2025_1613
RLSA-2025:1351
RLSA-2025:1443
RLSA-2025:1446
RLSA-2025:1582
RLSA-2025:1611
RLSA-2025:1613
SUSE-SU-2025:0232-1
SUSE-SU-2025:0233-1
SUSE-SU-2025:0234-1
SUSE-SU-2025:0237-1
SUSE-SU-2025:0284-1
SUSE-SU-2025_0232-1
SUSE-SU-2025_0234-1
SUSE-SU-2025_0237-1
SUSE-SU-2025_0284-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Node.Js
Red Hat
Red Os
Rocky Linux
Suse
Nghttp2