Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-65ch-62r8-g69g | node-forge is vulnerable to ASN.1 OID Integer Truncation |
Wed, 10 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 06 Dec 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:digitalbazaar:forge:*:*:*:*:*:node.js:*:* | |
| Metrics |
cvssV3_1
|
Fri, 28 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Digitalbazaar
Digitalbazaar forge |
|
| Vendors & Products |
Digitalbazaar
Digitalbazaar forge |
Wed, 26 Nov 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2. | |
| Title | node-forge ASN.1 OID Integer Truncation | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-28T18:25:02.440Z
Reserved: 2025-11-21T01:08:02.614Z
Link: CVE-2025-66030
Updated: 2025-11-28T18:24:55.244Z
Status : Analyzed
Published: 2025-11-26T23:15:49.237
Modified: 2025-12-06T00:20:44.720
Link: CVE-2025-66030
OpenCVE Enrichment
Updated: 2025-11-27T16:25:53Z
Github GHSA