Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15710 | In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No reference.
Tue, 20 May 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-401 | |
| References |
|
|
| Metrics |
cvssV3_0
|
Tue, 20 May 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22. | This CVE record has been withdrawn due to a duplicate entry CVE-2025-23165. |
| Metrics |
ssvc
|
Mon, 19 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 19 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-401 |
Mon, 19 May 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22. | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: REJECTED
Assigner: hackerone
Published:
Updated: 2025-05-20T21:59:31.237Z
Reserved: 2025-01-11T01:00:00.618Z
Link: CVE-2025-23122
Updated:
Status : Rejected
Published: 2025-05-19T02:15:17.003
Modified: 2025-05-20T22:15:18.907
Link: CVE-2025-23122
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD