FlawAtlas
Search the atlas
CVE-2025-23166 Not scored

CVE-2025-23166

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

Exploit probability 0.8%
Published May 19, 2025
Required by Not available
Last source change June 24, 2026

03 / CONNECTIONS

Connected vulnerabilities

related ALSA-2025:8467
related ALSA-2025:8468
related ALSA-2025:8493
related ALSA-2025:8506
related ALSA-2025:8514
related CGA-VV7X-RH59-X526
related OPENSUSE-SU-2025:15250-1
related OPENSUSE-SU-2025:15802-1
related SUSE-SU-2025:01878-1
related SUSE-SU-2025:01879-1
related SUSE-SU-2025:02039-1
related SUSE-SU-2025:02045-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-23166

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

View original source

05 / REFERENCES

Further evidence