CVE-2025-59464Disclosure(nodejs / node.js)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks memory, allowing remote clients to trigger steady memory growth through repeated TLS connections. Over time this can lead to resource exhaustion and denial of service.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
node.js

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-09: 103-09
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Heads up, #openSUSE Tumbleweed community! A new security advisory (2026-10311-1) is out for Corepack and Node.js 24, addressing CVE-2025-59464. Read more: 👉 https://tinyurl.com/9m9732ru #Security https://t.co/j5mQr4tgPi

    Post summary

    An openSUSE Tumbleweed advisory (2026-10311-1) has been released to address CVE-2025-59464 for Corepack and Node.js 24.

    0000079
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js---

Explore more