{"schema_version":"1.7.5","id":"CVE-2025-23166","published":"2025-05-19T02:15:17Z","modified":"2026-06-24T09:14:46.538823Z","aliases":["BIT-node-2025-23166","BIT-node-min-2025-23166"],"related":["ALSA-2025:8467","ALSA-2025:8468","ALSA-2025:8493","ALSA-2025:8506","ALSA-2025:8514","CGA-vv7x-rh59-x526","SUSE-SU-2025:01878-1","SUSE-SU-2025:01879-1","SUSE-SU-2025:02039-1","SUSE-SU-2025:02045-1","openSUSE-SU-2025:15250-1","openSUSE-SU-2025:15802-1","openSUSE-SU-2026:11110-1"],"details":"The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.","references":[{"type":"ARTICLE","url":"https://nodejs.org/en/blog/vulnerability/may-2025-security-releases"}]}