Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-554w-wpv2-vw27 | node-forge has ASN.1 Unbounded Recursion |
Sat, 06 Dec 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:digitalbazaar:forge:*:*:*:*:*:node.js:*:* | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 03 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 28 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Digitalbazaar
Digitalbazaar forge |
|
| Vendors & Products |
Digitalbazaar
Digitalbazaar forge |
Wed, 26 Nov 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2. | |
| Title | node-forge ASN.1 Unbounded Recursion | |
| Weaknesses | CWE-674 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-28T18:27:06.242Z
Reserved: 2025-11-21T01:08:02.614Z
Link: CVE-2025-66031
Updated: 2025-11-28T18:26:46.170Z
Status : Analyzed
Published: 2025-11-26T23:15:49.397
Modified: 2025-12-06T00:22:18.840
Link: CVE-2025-66031
OpenCVE Enrichment
Updated: 2025-11-27T16:26:23Z
Github GHSA