A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.
History

Tue, 25 Feb 2025 13:30:00 +0000

Type Values Removed Values Added
References

Fri, 14 Feb 2025 03:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9

Thu, 13 Feb 2025 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:8
Vendors & Products Redhat
Redhat enterprise Linux

Fri, 07 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Feb 2025 07:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.
References
Metrics cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Wed, 29 Jan 2025 02:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title nodejs: GOAWAY HTTP/2 frames cause memory leak outside heap
Weaknesses CWE-400
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2025-02-07T07:09:25.804Z

Updated: 2025-02-25T13:07:47.090Z

Reserved: 2025-01-10T19:05:52.771Z

Link: CVE-2025-23085

cve-icon Vulnrichment

Updated: 2025-02-25T13:07:47.090Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-07T07:15:15.810

Modified: 2025-02-25T13:15:11.103

Link: CVE-2025-23085

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-01-21T00:00:00Z

Links: CVE-2025-23085 - Bugzilla