Vulnerabilities/

node-forge has ASN.1 Unbounded Recursion

Severity:
High

Description

An Uncontrolled Recursion (CWE-674) vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs.

Recommendation

Update the node-forge package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
node-forge
Anything's wrong? Let us know Last updated on November 26, 2025