Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-12816

Опубликовано: 25 нояб. 2025
Источник: redhat
CVSS3: 8.7
EPSS Низкий

Описание

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.

A flaw was found in node-forge. This vulnerability allows unauthenticated attackers to bypass downstream cryptographic verifications and security decisions via crafting ASN.1 (Abstract Syntax Notation One) structures to desynchronize schema validations, yielding a semantic divergence.

Отчет

This vulnerability is rated Important for Red Hat products due to an interpretation conflict in the node-forge library. An unauthenticated attacker could exploit this flaw by crafting malicious ASN.1 structures, leading to a bypass of cryptographic verifications and security decisions in affected applications. This impacts various Red Hat products that utilize node-forge for cryptographic operations.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4io.cryostat-cryostatNot affected
Gatekeeper 3gatekeeper/gatekeeper-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-operator-bundleWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-proxy-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel9-operatorWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-curator5-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-view-plugin-rhel9Will not fix
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-179
https://bugzilla.redhat.com/show_bug.cgi?id=2417097node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications

EPSS

Процентиль: 52%
0.00753
Низкий

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
9 месяцев назад

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.

CVSS3: 8.6
nvd
9 месяцев назад

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.

CVSS3: 8.6
msrc
9 месяцев назад

CVE-2025-12816

CVSS3: 8.6
debian
9 месяцев назад

An interpretation-conflict (CWE-436) vulnerability in node-forge versi ...

CVSS3: 8.6
github
9 месяцев назад

node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization

EPSS

Процентиль: 52%
0.00753
Низкий

8.7 High

CVSS3