* This vulnerability affects Node.js v24.x users.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21940 | The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an attacker can generate collisions even without knowing the hash-seed. * This vulnerability affects Node.js v24.x users. |
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 29 Jul 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | nodejs: Node.js Rapidhash HashDoS Vulnerability | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 21 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-407 | |
| Metrics |
ssvc
|
Fri, 18 Jul 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an attacker can generate collisions even without knowing the hash-seed. * This vulnerability affects Node.js v24.x users. | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-11-04T21:09:46.228Z
Reserved: 2025-02-20T01:00:01.798Z
Link: CVE-2025-27209
Updated: 2025-11-04T21:09:46.228Z
Status : Deferred
Published: 2025-07-18T23:15:23.190
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-27209
OpenCVE Enrichment
Updated: 2025-07-21T15:17:06Z
EUVD