CVE-2025-23085

EUVD-2025-3113
A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions.

This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
Debian logo
Debian Releases
Debian Product
Codename
nodejs
bookworm
18.20.4+dfsg-1~deb12u2
fixed
bookworm (security)
18.20.4+dfsg-1~deb12u2
fixed
bullseye
vulnerable
bullseye (security)
12.22.12~dfsg-1~deb11u8
fixed
forky
24.18.0+dfsg+~cs24.13.2-1
fixed
sid
24.18.0+dfsg+~cs24.13.2-1
fixed
trixie
20.19.2+dfsg-1+deb13u2
fixed
trixie (security)
20.19.2+dfsg-1+deb13u2
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
nodejs18
suse enterprise server 12 SP5
18.20.6-8.33.1
fixed
suse enterprise server 15 SP4
18.20.6-150400.9.33.1
fixed
suse enterprise server 15 SP5
18.20.6-150400.9.33.1
fixed
nodejs18-devel
suse enterprise server 12 SP5
18.20.6-8.33.1
fixed
suse enterprise server 15 SP4
18.20.6-150400.9.33.1
fixed
suse enterprise server 15 SP5
18.20.6-150400.9.33.1
fixed
nodejs18-docs
suse enterprise server 12 SP5
18.20.6-8.33.1
fixed
suse enterprise server 15 SP4
18.20.6-150400.9.33.1
fixed
suse enterprise server 15 SP5
18.20.6-150400.9.33.1
fixed
nodejs20
suse enterprise sap 15 SP6
20.18.2-150600.3.9.1
fixed
suse enterprise server 15 SP5
20.18.2-150500.11.18.1
fixed
suse enterprise server 15 SP6
20.18.2-150600.3.9.1
fixed
nodejs20-devel
suse enterprise sap 15 SP6
20.18.2-150600.3.9.1
fixed
suse enterprise server 15 SP5
20.18.2-150500.11.18.1
fixed
suse enterprise server 15 SP6
20.18.2-150600.3.9.1
fixed
nodejs20-docs
suse enterprise sap 15 SP6
20.18.2-150600.3.9.1
fixed
suse enterprise server 15 SP5
20.18.2-150500.11.18.1
fixed
suse enterprise server 15 SP6
20.18.2-150600.3.9.1
fixed
nodejs22
suse enterprise sap 15 SP6
22.13.1-150600.13.6.1
fixed
suse enterprise server 15 SP6
22.13.1-150600.13.6.1
fixed
nodejs22-devel
suse enterprise sap 15 SP6
22.13.1-150600.13.6.1
fixed
suse enterprise server 15 SP6
22.13.1-150600.13.6.1
fixed
nodejs22-docs
suse enterprise sap 15 SP6
22.13.1-150600.13.6.1
fixed
suse enterprise server 15 SP6
22.13.1-150600.13.6.1
fixed
npm18
suse enterprise server 12 SP5
18.20.6-8.33.1
fixed
suse enterprise server 15 SP4
18.20.6-150400.9.33.1
fixed
suse enterprise server 15 SP5
18.20.6-150400.9.33.1
fixed
npm20
suse enterprise sap 15 SP6
20.18.2-150600.3.9.1
fixed
suse enterprise server 15 SP5
20.18.2-150500.11.18.1
fixed
suse enterprise server 15 SP6
20.18.2-150600.3.9.1
fixed
npm22
suse enterprise sap 15 SP6
22.13.1-150600.13.6.1
fixed
suse enterprise server 15 SP6
22.13.1-150600.13.6.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
nodejs
Amazon Linux 2023
1:18.20.6-1.amzn2023.0.1
fixed
nodejs-debuginfo
Amazon Linux 2023
1:18.20.6-1.amzn2023.0.1
fixed
nodejs-debugsource
Amazon Linux 2023
1:18.20.6-1.amzn2023.0.1
fixed
nodejs-devel
Amazon Linux 2023
1:18.20.6-1.amzn2023.0.1
fixed
nodejs-docs
Amazon Linux 2023
1:18.20.6-1.amzn2023.0.1
fixed
nodejs-full-i18n
Amazon Linux 2023
1:18.20.6-1.amzn2023.0.1
fixed
nodejs-libs
Amazon Linux 2023
1:18.20.6-1.amzn2023.0.1
fixed
nodejs-libs-debuginfo
Amazon Linux 2023
1:18.20.6-1.amzn2023.0.1
fixed
nodejs-npm
Amazon Linux 2023
1:10.8.2-1.18.20.6.1.amzn2023.0.1
fixed
nodejs20
Amazon Linux 2023
1:20.18.2-1.amzn2023.0.1
fixed
nodejs20-debuginfo
Amazon Linux 2023
1:20.18.2-1.amzn2023.0.1
fixed
nodejs20-debugsource
Amazon Linux 2023
1:20.18.2-1.amzn2023.0.1
fixed
nodejs20-devel
Amazon Linux 2023
1:20.18.2-1.amzn2023.0.1
fixed
nodejs20-docs
Amazon Linux 2023
1:20.18.2-1.amzn2023.0.1
fixed
nodejs20-full-i18n
Amazon Linux 2023
1:20.18.2-1.amzn2023.0.1
fixed
nodejs20-libs
Amazon Linux 2023
1:20.18.2-1.amzn2023.0.1
fixed
nodejs20-libs-debuginfo
Amazon Linux 2023
1:20.18.2-1.amzn2023.0.1
fixed
nodejs20-npm
Amazon Linux 2023
1:10.8.2-1.20.18.2.1.amzn2023.0.1
fixed
v8-10.2-devel
Amazon Linux 2023
3:10.2.154.26-1.18.20.6.1.amzn2023.0.1
fixed
v8-11.3-devel
Amazon Linux 2023
3:11.3.244.8-1.20.18.2.1.amzn2023.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
nodejs
Azure Linux 3.0
0:20.14.0-5.azl3
fixed
nodejs18
CBL-Mariner 2.0
0:18.20.3-3.cm2
fixed