Количество 21
Количество 21

SUSE-SU-2025:01879-1
Security update for nodejs22

SUSE-SU-2025:01878-1
Security update for nodejs22
ELSA-2025-8493
ELSA-2025-8493: nodejs22 security update (IMPORTANT)

SUSE-SU-2025:02045-1
Security update for nodejs20

SUSE-SU-2025:02039-1
Security update for nodejs20

CVE-2025-23165
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVE-2025-23165
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVE-2025-23165
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.

CVE-2025-23165
CVE-2025-23165
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a ...

CVE-2025-23166
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVE-2025-23166
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVE-2025-23166
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVE-2025-23166
CVE-2025-23166
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowExce ...
GHSA-gcf6-vgcr-474f
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.
GHSA-rrjv-57mm-j6cm
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.
ELSA-2025-8514
ELSA-2025-8514: nodejs:20 security update (IMPORTANT)
ELSA-2025-8506
ELSA-2025-8506: nodejs:22 security update (IMPORTANT)
ELSA-2025-8468
ELSA-2025-8468: nodejs:20 security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | SUSE-SU-2025:01879-1 Security update for nodejs22 | около 2 месяцев назад | ||
![]() | SUSE-SU-2025:01878-1 Security update for nodejs22 | около 2 месяцев назад | ||
ELSA-2025-8493 ELSA-2025-8493: nodejs22 security update (IMPORTANT) | около 1 месяца назад | |||
![]() | SUSE-SU-2025:02045-1 Security update for nodejs20 | около 2 месяцев назад | ||
![]() | SUSE-SU-2025:02039-1 Security update for nodejs20 | около 2 месяцев назад | ||
![]() | CVE-2025-23165 In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22. | CVSS3: 3.7 | 0% Низкий | 3 месяца назад |
![]() | CVE-2025-23165 In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22. | CVSS3: 3.7 | 0% Низкий | 3 месяца назад |
![]() | CVE-2025-23165 In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22. | CVSS3: 3.7 | 0% Низкий | 3 месяца назад |
![]() | CVSS3: 3.7 | 0% Низкий | 27 дней назад | |
CVE-2025-23165 In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a ... | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
![]() | CVE-2025-23166 The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад |
![]() | CVE-2025-23166 The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад |
![]() | CVE-2025-23166 The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад |
![]() | CVSS3: 7.5 | 0% Низкий | 20 дней назад | |
CVE-2025-23166 The C++ method SignTraits::DeriveBits() may incorrectly call ThrowExce ... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-gcf6-vgcr-474f In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22. | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
GHSA-rrjv-57mm-j6cm The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
ELSA-2025-8514 ELSA-2025-8514: nodejs:20 security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2025-8506 ELSA-2025-8506: nodejs:22 security update (IMPORTANT) | 2 месяца назад | |||
ELSA-2025-8468 ELSA-2025-8468: nodejs:20 security update (IMPORTANT) | 2 месяца назад |
Уязвимостей на страницу