Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5gfm-wpxj-wjgq | node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization |
Fri, 02 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:digitalbazaar:forge:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Digitalbazaar node-forge
|
Tue, 30 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Digitalbazaar node-forge
|
|
| CPEs | cpe:2.3:a:digitalbazaar:node-forge:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Digitalbazaar node-forge
|
Sat, 13 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-179 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 27 Nov 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Digitalbazaar
Digitalbazaar forge |
|
| Vendors & Products |
Digitalbazaar
Digitalbazaar forge |
Tue, 25 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 25 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-436 | |
| Metrics |
cvssV3_1
|
Tue, 25 Nov 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 25 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions. | |
| Title | CVE-2025-12816 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2025-11-25T21:04:09.432Z
Reserved: 2025-11-06T17:11:38.255Z
Link: CVE-2025-12816
Updated: 2025-11-25T21:04:09.432Z
Status : Analyzed
Published: 2025-11-25T20:15:58.870
Modified: 2026-01-02T19:02:08.980
Link: CVE-2025-12816
OpenCVE Enrichment
Updated: 2025-11-27T09:45:31Z
Github GHSA