CVE-2025-12816

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:digitalbazaar:forge:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2025-11-25 20:15

Updated : 2026-01-02 19:02


NVD link : CVE-2025-12816

Mitre link : CVE-2025-12816

CVE.ORG link : CVE-2025-12816


JSON object : View

Products Affected

digitalbazaar

  • forge
CWE
CWE-436

Interpretation Conflict