Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3776-1 | nodejs security update |
Debian DLA |
DLA-3886-1 | nodejs security update |
Debian DSA |
DSA-5991-1 | nodejs security update |
EUVD |
EUVD-2023-50975 | Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key. |
Tue, 04 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 09 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nodejs
Nodejs nodejs |
|
| CPEs | cpe:2.3:a:nodejs:nodejs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nodejs
Nodejs nodejs |
|
| Metrics |
cvssV3_1
|
ssvc
|
Sat, 07 Sep 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Node.js. The privateDecrypt() API of the crypto library may allow a covert timing side-channel during PKCS#1 v1.5 padding error handling. This issue revealed significant timing differences in decryption for valid and invalid ciphertexts, which may allow a remote attacker to decrypt captured RSA ciphertexts or forge signatures, especially in scenarios involving API endpoints processing JSON Web Encryption messages. | Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key. |
| References |
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-11-04T18:18:49.086Z
Reserved: 2023-10-27T01:00:13.401Z
Link: CVE-2023-46809
Updated: 2025-11-04T18:18:49.086Z
Status : Deferred
Published: 2024-09-07T16:15:02.343
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-46809
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD