CVE-2025-12816

Aliases:GHSA-5gfm-wpxj-wjgq
Analyzed
Published: 25 Nov 2025, 19:15
Last modified:25 Nov 2025, 21:04

Vulnerability Summary

Overall Risk (default)
medium
44/100
CVSS Score
8.6 HIGH
v3.1 (cve.org)
EPSS Score
0.07% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

25 Nov 2025, 19:15
Published
Vulnerability first disclosed
25 Nov 2025, 21:04
Last Modified
Vulnerability information updated

Description

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.

CVSS Metrics

  • v4.0HIGHScore: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  • v3.1HIGHScore: 8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.07% Percentile: 22%

Techniques & Countermeasures

  • CWE-436Interpretation Conflict

    Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

Affected Systems

  • digital bazaarforge

    ≤ 1.3.1

  • digital bazaarnode-forge

    ≤ 1.3.1

  • digitalbazaarforge

    ≤ 1.3.1

  • Npmnode-forge

    < 1.3.2

References (13)