CVE-2025-59464

EUVD-2026-3340
A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks memory, allowing remote clients to trigger steady memory growth through repeated TLS connections. Over time this can lead to resource exhaustion and denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Affected Products (NVD)
VendorProductVersion
nodejsnode.js
24.0.0 ≤
𝑥
< 24.12.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nodejs
bookworm
18.20.4+dfsg-1~deb12u1
fixed
bookworm (security)
18.20.4+dfsg-1~deb12u2
fixed
bullseye
12.22.12~dfsg-1~deb11u4
fixed
bullseye (security)
12.22.12~dfsg-1~deb11u8
fixed
forky
24.15.0+dfsg+~cs24.12.2-1
fixed
sid
24.15.0+dfsg+~cs24.12.2-1
fixed
trixie
20.19.2+dfsg-1+deb13u2
fixed
trixie (security)
20.19.2+dfsg-1+deb13u2
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
nodejs24
suse enterprise sap 15 SP7
24.14.1-150700.15.8.1
fixed
suse enterprise server 15 SP7
24.14.1-150700.15.8.1
fixed
nodejs24-devel
suse enterprise sap 15 SP7
24.14.1-150700.15.8.1
fixed
suse enterprise server 15 SP7
24.14.1-150700.15.8.1
fixed
nodejs24-docs
suse enterprise sap 15 SP7
24.14.1-150700.15.8.1
fixed
suse enterprise server 15 SP7
24.14.1-150700.15.8.1
fixed
npm24
suse enterprise sap 15 SP7
24.14.1-150700.15.8.1
fixed
suse enterprise server 15 SP7
24.14.1-150700.15.8.1
fixed