PT-2025-48201 · Unknown+1 · Node-Forge+1

Published

2025-11-26

·

Updated

2026-04-01

·

CVE-2025-66030

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions node-forge versions 1.3.1 and below
Description An Integer Overflow issue exists in node-forge, a native implementation of Transport Layer Security in JavaScript. The flaw resides in the parsing of ASN.1 structures containing OIDs with oversized arcs. Due to 32-bit bitwise truncation during decoding, these arcs may be interpreted as smaller, trusted OIDs, potentially bypassing security checks reliant on OID-based decisions.
Recommendations Update to node-forge version 1.3.2 or later.

Exploit

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

AZL-71131
CVE-2025-66030
GHSA-65CH-62R8-G69G

Affected Products

Debian
Node-Forge