CVE-2025-23085

Updated: 2025-08-20 02:31:24.710054

Description:

A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x MEDIUM 5.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU nodejs 16.20.2 5.3 MEDIUM Released CLSA-2025:1756305640 2025-08-28 00:57:10
TuxCare 9.6 ESU nodejs 16.20.2 5.3 MEDIUM Released CLSA-2026:1770717358 2026-02-10 13:41:48