[CIVN-2025-0149] Multiple Vulnerabilities in Node.js
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Node.js
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Node.js versions prior to v20.19.4 (LTS)
Node.js versions prior to v22.17.1 (LTS)
Node.js versions prior to v24.4.1 (Current)
Overview
Multiple Vulnerabilities have been reported in Node.js which could be exploited by an attacker to bypass security restrictions or can cause Denial of Service condition on the targeted system.
Target Audience:
All end-user organizations and individuals using Node.js.
Risk Assessment:
High risk of unauthorized access to sensitive information and service disruption.
Impact Assessment:
Potential for data theft, system instability or system crash.
Description
Node.js is a widely used, open-source, cross-platform JavaScript runtime environment designed for building scalable and high-performance network applications.
These vulnerabilities exist in Node.js due to HashDoS attack in the V8 engine and improper input sanitization of path.normalize() function.
Successful Exploitation of these vulnerabilities could allow attackers to bypass security restrictions or can cause Denial of Service condition on the targeted system.
Solution
Apply appropriate updates as mentioned by the Vendor:
https://nodejs.org/en/blog/vulnerability/july-2025-security-releases
Vendor Information
Node.js
https://nodejs.org/en/blog/vulnerability/july-2025-security-releases
References
Node.js
https://nodejs.org/en/blog/vulnerability/july-2025-security-releases
CVE Name
CVE-2025-27209
CVE-2025-27210
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmh/PnIACgkQ3jCgcSdc
ys+g6xAAjsqSBlwqVKZnyL1N9uD7D2Ji1f+hOcWcXnRs9EJ+/sUG4QJiKg7o+6nx
IxFEe2d/xf3zoMukUXILmzGvLj0B0tPq83focvhVO4OuTbKYibuyv30pXg6s8OF/
x0Ugy/2fBWgBxTFbSeAoPcvcVq3Iw9VwBvSziDnGM//TDyi+gKKob9r4CjEaPBfW
g3I1k+3GBuWCbIIPyfSzeNud+4KapBjqXQQZP9eeWOVhA2L2wGCGFXq+JHxccXXi
lzSPrri4dcyG3gfIaqx+RjLbxgUSxkecQD95Paln/eJIPPE64s76SqBzcpTUfypp
7EbP7WQn9ELurg75Roi08RzBWRlsaPK8s76dYaWDTsSik5upLdLoImX/+vXBp3Qu
x7ZnxeatZRecPw4tTFl5ItVeHNeZHHb2zlacVlXUTlcDdgP1cukwFcDXrT5miIlC
wgmVZCmfiy1cuFFA1peaJZO+kEIID0PhfCqzSuP3Z0V/WyDDydYHVjKuoVbxgqpu
KawcylRnvT5kckRnRnTE0fFOr8JOpZYUNMiYbrMDiXao5WEc80/rabRPCMVv15JY
1p/8xWbfUzQcVHW/pvYYt93f6DGc7AdNQUNA7G4+wEWyZigZ4k9ptg4a98KPHqfw
ZVBekEpeSew2y9uhVFP/OYPj3hrLR4g2aFGcY8EElJABHE4ijek=
=OVIa
—–END PGP SIGNATURE—–