/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2025-66031

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-66031

Severity

Unknown

Summary

node-forge ASN.1 Unbounded Recursion

Description

Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing