CVE-2025-12816

HIGH

node-forge <1.3.1 - SSRF

Title source: llm

Description

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.

Scores

CVSS v3 8.6
EPSS 0.0006
EPSS Percentile 18.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Classification

CWE
CWE-436
Status published

Affected Products (2)

digitalbazaar/forge < 1.3.1
npm/node-forge < 1.3.2npm

Timeline

Published Nov 25, 2025
Tracked Since Feb 18, 2026