Количество 5
Количество 5
CVE-2025-66031
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
CVE-2025-66031
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
CVE-2025-66031
node-forge ASN.1 Unbounded Recursion
CVE-2025-66031
Forge (also called `node-forge`) is a native implementation of Transpo ...
GHSA-554w-wpv2-vw27
node-forge has ASN.1 Unbounded Recursion
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-66031 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2. | CVSS3: 7.5 | 0% Низкий | 24 дня назад | |
CVE-2025-66031 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2. | CVSS3: 7.5 | 0% Низкий | 24 дня назад | |
CVE-2025-66031 node-forge ASN.1 Unbounded Recursion | 0% Низкий | 19 дней назад | ||
CVE-2025-66031 Forge (also called `node-forge`) is a native implementation of Transpo ... | CVSS3: 7.5 | 0% Низкий | 24 дня назад | |
GHSA-554w-wpv2-vw27 node-forge has ASN.1 Unbounded Recursion | 0% Низкий | 24 дня назад |
Уязвимостей на страницу