CVE-2025-23166

Source
https://cve.org/CVERecord?id=CVE-2025-23166
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-23166.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-23166
Aliases
Downstream
ALPINE (1)
AZL (2)
BELL (1)
CGA (6)
CLSA (2)
DEBIAN (1)
ECHO (1)
MGASA (1)
MINI (5)
OESA (2)
openSUSE (3)
RHSA (6)
RLSA (5)
ROOT (1)
SUSE (6)
UBUNTU (1)
Related
Published
2025-05-19T02:15:17Z
Modified
2026-09-18T18:11:38Z
Summary
[none]
Details

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

References

Affected packages