CVE-2025-23085
published 2025-02-07CVE-2025-23085: A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected…
PriorityP426medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
1.33%
68.0th percentile
A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions.
This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 12.22.12~dfsg-1~deb11u6 (bullseye) | nodejs 12.22.12~dfsg-1~deb11u6 (bullseye) |
| nodejs | node | >= 10.0 < 10.* | 10.* |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.* | 12.* |
| nodejs | node | >= 13.0 < 13.* | 13.* |
| nodejs | node | >= 14.0 < 14.* | 14.* |
| nodejs | node | >= 15.0 < 15.* | 15.* |
| nodejs | node | >= 16.0 < 16.* | 16.* |
| nodejs | node | >= 17.0 < 17.* | 17.* |
| nodejs | node | >= 18.0 < 18.20.6 | 18.20.6 |
| nodejs | node | >= 19.0 < 19.* | 19.* |
| nodejs | node | >= 20.0 < 20.18.2 | 20.18.2 |
| nodejs | node | >= 21.0 < 21.* | 21.* |
| nodejs | node | >= 22.0 < 22.13.1 | 22.13.1 |
| nodejs | node | >= 23.0 < 23.6.1 | 23.6.1 |
| nodejs | node | >= 4.0 < 4.* | 4.* |
| nodejs | node | >= 5.0 < 5.* | 5.* |
| nodejs | node | >= 6.0 < 6.* | 6.* |
| nodejs | node | >= 7.0 < 7.* | 7.* |
| nodejs | node | >= 8.0 < 8.* | 8.* |
| nodejs | node | >= 9.0 < 9.* | 9.* |
| nodejs | nodejs | >= 0 < 22.13.1-r0 | 22.13.1-r0 |
| nodejs | nodejs | >= 0 < 22.13.1-r0 | 22.13.1-r0 |
| nodejs | nodejs | >= 0 < 22.13.1-r0 | 22.13.1-r0 |
| nodejs | nodejs | >= 0 < 12.22.12~dfsg-1~deb11u6 | 12.22.12~dfsg-1~deb11u6 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_oracle6.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-23085: A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification
osv·2025-02-07·CVSS 5.3
CVE-2025-23085 [MEDIUM] CVE-2025-23085: A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification
A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.
GHSA
GHSA-qv9x-c8c9-rpr8: A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification
ghsa_unreviewed·2025-02-07
CVE-2025-23085 [MEDIUM] CWE-401 GHSA-qv9x-c8c9-rpr8: A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification
A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions.
This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.
OSV
CVE-2025-23085: A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification
osv·2025-02-07·CVSS 5.3
CVE-2025-23085 [MEDIUM] CVE-2025-23085: A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification
A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions.
This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Node.js) — CVE-2025-23085
vendor_oracle·2025-07-15·CVSS 6.5
CVE-2025-23085 [MEDIUM] Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Node.js) — CVE-2025-23085
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Node.js) vulnerability
CVE: CVE-2025-23085
CVSS: 6.5
Protocol: Oracle Net
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Red Hat
nodejs: GOAWAY HTTP/2 frames cause memory leak outside heap
vendor_redhat·2025-01-21·CVSS 5.3
CVE-2025-23085 [MEDIUM] CWE-400 nodejs: GOAWAY HTTP/2 frames cause memory leak outside heap
nodejs: GOAWAY HTTP/2 frames cause memory leak outside heap
A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions.
This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.
A vulnerability was found in NodeJS when handling HTTP/2 connections, where the remote peer abruptly closes the socket without sending the proper HTTP/2 notification to the server, leading to a memory leak. This flaw allows an attacker to force the targeted process in the targeted hos
Debian
CVE-2025-23085: nodejs - A memory leak could occur when a remote peer abruptly closes the socket without ...
vendor_debian·2025·CVSS 5.3
CVE-2025-23085 [MEDIUM] CVE-2025-23085: nodejs - A memory leak could occur when a remote peer abruptly closes the socket without ...
A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions. This vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.
Scope: local
bookworm: open
bullseye: resolved (fixed in 12.22.12~dfsg-1~deb11u6)
forky: resolved (fixed in 20.18.2+dfsg-1)
sid: resolved (fixed in 20.18.2+dfsg-1)
trixie: resolved (fixed in 20.19.2+dfsg-1+deb13u1)
No detection rules found.
No public exploits indexed.
2025-02-07
Published