Denial of Service Vulnerability in Mozilla Rhino JavaScript Engine
CVE-2025-66453
What is CVE-2025-66453?
The Rhino JavaScript engine is susceptible to a Denial of Service vulnerability where an attacker can exploit the toFixed() function by passing a maliciously crafted floating-point number. This could result in excessive CPU usage, rendering applications unresponsive. The issue arises from a flawed call stack that leads to computationally intensive tasks when processing small numbers. The vulnerability has been addressed in versions 1.8.1, 1.7.15.1, and 1.7.14.1, ensuring better performance and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
rhino >= 1.8.0, < 1.8.1 < 1.8.0, 1.8.1
rhino >= 1.7.15, < 1.7.15.1 < 1.7.15, 1.7.15.1
rhino < 1.7.14.1 < 1.7.14.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved