CVE-2025-23166
Awaiting Analysis Awaiting Analysis - Queue

BaseFortify

Vulnerability report for CVE-2025-23166, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2025-05-19

Last updated on: 2025-05-19

Assigner: HackerOne

Description

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2025-05-19
Last Modified
2025-05-19
Generated
2026-09-27
AI Q&A
2025-05-19
EPSS Evaluated
2026-09-26
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability is due to an error in the C++ method SignTraits::DeriveBits() within the Node.js cryptography library. The method may incorrectly call ThrowException() when it processes user-supplied inputs in a background thread. This improper exception handling can crash the Node.js process, potentially allowing an adversary to remotely disrupt the runtime. [1]

Impact Analysis

If you rely on Node.js for your applications or services, this vulnerability can lead to unexpected crashes of your Node.js processes. Such crashes, triggered by specially crafted inputs, can result in denial of service or instability, impacting the availability of your services. [1]

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-23166. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart