CVE-2025-12816 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desyn…
High CVSS: 8.6

CVE-2025-12816

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.
Vendor
Digitalbazaar
Product
Forge
CWE
CWE-436
Yayın Tarihi
2025-11-25 20:15:58
Güncelleme
2026-01-02 19:02:08
Source Identifier
cret@cert.org
KEV Date Added
-

Kategoriler

Referanslar