Junglewise Threat Intelligence

CVE-2025-66031: node-forge ASN.1 unbounded recursion denial of service

CVE-2025-66031 · Severity: medium · CVSS 4 · Published 2025-11-26

Technologies: Digital Bazaar Forge, node-forge (npm). Vendors: Digital Bazaar, npm.

Executive brief

node-forge is a cryptography library used in Node.js applications to handle TLS connections and certificate parsing. An attacker can crash servers or clients by sending specially crafted ASN.1 structures that trigger excessive recursion, causing the process to exhaust its call stack and become unavailable. This affects any application using node-forge to process untrusted certificate or cryptographic data.

Technical details

An uncontrolled recursion vulnerability (CWE-674) exists in the node-forge asn1.fromDer function within lib/asn1.js. The ASN.1 DER parser (_fromDer) recursively processes constructed types (SEQUENCE, SET, etc.) without enforcing a depth limit. An attacker can craft a small DER blob with deeply nested constructed TLV (Tag-Length-Value) structures that causes the Node.js V8 engine to exhaust its call stack, throwing "RangeError: Maximum call stack size exceeded" and crashing the process. This is a remote, unauthenticated denial-of-service attack requiring no special privileges or user interaction. The vulnerability affects node-forge versions 1.3.1 and earlier; a fix was released in version 1.3.2 by adding recursion depth limits.

Affected products

  • Digital Bazaar node-forge < 1.3.2

Timeline

  • 2025-11-26: disclosed: GHSA-554w-wpv2-vw27 published
  • 2025-11-26: patched: Fix released in version 1.3.2

References

Related threats