Node.js Software Vulnerability Allowing Remote Crash via User Inputs
CVE-2025-23166
7.5HIGH
What is CVE-2025-23166?
A flaw in the C++ method SignTraits::DeriveBits() in Node.js could lead to unexpected behavior when processing user inputs in a background thread. This vulnerability can result in the Node.js process crashing due to the improper handling of cryptographic operations applied to untrusted data. Adversaries may exploit this to disrupt service by inducing crashes remotely, emphasizing the importance of secure input handling in software design.
Affected Version(s)
node 20.19.1
node 22.15.0
node 23.11.0