CVE-2025-23166
EUVD-2025-1570219.05.2025, 02:15
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| nodejs |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| nodejs20 |
| ||||||||
| nodejs20-devel |
| ||||||||
| nodejs20-docs |
| ||||||||
| nodejs22 |
| ||||||||
| nodejs22-devel |
| ||||||||
| nodejs22-docs |
| ||||||||
| npm20 |
| ||||||||
| npm22 |
|
Common Weakness Enumeration