Denial of Service Vulnerability in Mozilla Rhino JavaScript Engine
CVE-2025-66453

5.5MEDIUM

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
3 December 2025

What is CVE-2025-66453?

The Rhino JavaScript engine is susceptible to a Denial of Service vulnerability where an attacker can exploit the toFixed() function by passing a maliciously crafted floating-point number. This could result in excessive CPU usage, rendering applications unresponsive. The issue arises from a flawed call stack that leads to computationally intensive tasks when processing small numbers. The vulnerability has been addressed in versions 1.8.1, 1.7.15.1, and 1.7.14.1, ensuring better performance and security.

Affected Version(s)

rhino >= 1.8.0, < 1.8.1 < 1.8.0, 1.8.1

rhino >= 1.7.15, < 1.7.15.1 < 1.7.15, 1.7.15.1

rhino < 1.7.14.1 < 1.7.14.1

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-66453 : Denial of Service Vulnerability in Mozilla Rhino JavaScript Engine