FlawAtlas
Search the atlas
CVE-2025-23085 Not scored

CVE-2025-23085

A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.

Exploit probability 1.3%
Published February 7, 2025
Required by Not available
Last source change June 24, 2026

03 / CONNECTIONS

Connected vulnerabilities

related ALSA-2025:1351
related ALSA-2025:1443
related ALSA-2025:1446
related ALSA-2025:1582
related ALSA-2025:1611
related ALSA-2025:1613
related CGA-73RP-JR89-9J82
related OPENSUSE-SU-2025:14706-1
related OPENSUSE-SU-2025:15802-1
related RLSA-2025:1443
related SUSE-SU-2025:0232-1
related SUSE-SU-2025:0233-1
related SUSE-SU-2025:0234-1
related SUSE-SU-2025:0237-1
related SUSE-SU-2025:0284-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-23085

A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.

View original source

05 / REFERENCES

Further evidence