/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2023-30588

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-30588

CGA ID

CGA-5994-9mfc-rcww

Severity

5.3

Medium

CVSS V3

Description

When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect termination occurs making it susceptible to DoS attacks when the attacker could force interruptions of application processing, as the process terminates when accessing public key info of provided certificates from user code. The current context of the users will be gone, and that will cause a DoS scenario. This vulnerability affects all active Node.js versions v16, v18, and, v20.

References

  • https://images.chainguard.dev/security/CGA-5994-9mfc-rcww

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs