CVE-2025-23166

Name
CVE-2025-23166
Description
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
support@hackerone.com https://nodejs.org/en/blog/vulnerability/may-2025-security-releases

Match rules

CPE URI Source package Min version Max version
node >= 0 <= 20.19.1
node >= 0 <= 22.15.0
node >= 0 <= 23.11.0
node >= 0 <= 24.0.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nodejs edge-main 22.16.0-r0 Jakub Jirutka <jakub@jirutka.cz> fixed
nodejs 3.21-main 22.15.1-r0 Jakub Jirutka <jakub@jirutka.cz> fixed