CVE Database
/

CVE-2025-12816

Back to search

CVE-2025-12816

Published: Nov 25, 2025

Modified: Nov 25, 2025

PUBLISHED

Description

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.

VendorProductVersions

Digital Bazaar

node-forge

affected
0 - <= 1.3.1

Digital Bazaar

forge

affected
0 - <= 1.3.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now