PT-2025-48202 · Unknown+1 · Node-Forge+1
Published
2025-11-26
·
Updated
2026-04-01
·
CVE-2025-66031
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
node-forge versions 1.3.1 and below
Description
An uncontrolled recursion issue exists in node-forge, a native implementation of Transport Layer Security in JavaScript. The issue allows remote, unauthenticated attackers to create complex ASN.1 structures that cause unbounded recursive parsing. This can lead to a Denial-of-Service (DoS) condition through stack exhaustion when processing untrusted DER inputs.
Recommendations
Update to version 1.3.2 or later.
Exploit
Fix
DoS
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Node-Forge