CVE-2025-23165
published 2025-05-19CVE-2025-23165: In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently…
PriorityP412low3.7CVSS 3.0
AVNACHPRNUINSUCNINAL
EPSS
0.48%
38.7th percentile
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 20.19.2+dfsg-1 (forky) | nodejs 20.19.2+dfsg-1 (forky) |
| nodejs | node | >= 10.0 < 10.* | 10.* |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.* | 12.* |
| nodejs | node | >= 13.0 < 13.* | 13.* |
| nodejs | node | >= 14.0 < 14.* | 14.* |
| nodejs | node | >= 15.0 < 15.* | 15.* |
| nodejs | node | >= 16.0 < 16.* | 16.* |
| nodejs | node | >= 17.0 < 17.* | 17.* |
| nodejs | node | >= 18.0 < 18.* | 18.* |
| nodejs | node | >= 19.0 < 19.* | 19.* |
| nodejs | node | 20.0 – 20.19.1 | — |
| nodejs | node | >= 21.0 < 21.* | 21.* |
| nodejs | node | 22.0 – 22.15.0 | — |
| nodejs | node | >= 4.0 < 4.* | 4.* |
| nodejs | node | >= 5.0 < 5.* | 5.* |
| nodejs | node | >= 6.0 < 6.* | 6.* |
| nodejs | node | >= 7.0 < 7.* | 7.* |
| nodejs | node | >= 8.0 < 8.* | 8.* |
| nodejs | node | >= 9.0 < 9.* | 9.* |
| nodejs | nodejs | >= 0 < 22.15.1-r0 | 22.15.1-r0 |
| nodejs | nodejs | >= 0 < 20.19.2+dfsg-1 | 20.19.2+dfsg-1 |
| nodejs | nodejs | >= 0 < 20.19.2+dfsg-1 | 20.19.2+dfsg-1 |
CVSS provenance
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
osv3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gcf6-vgcr-474f: In Node
ghsa_unreviewed·2025-05-19
CVE-2025-23165 [LOW] CWE-401 GHSA-gcf6-vgcr-474f: In Node
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service.
Impact:
* This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.
OSV
CVE-2025-23165: In Node
osv·2025-05-19·CVSS 3.7
CVE-2025-23165 [LOW] CVE-2025-23165: In Node
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.
OSV
CVE-2025-23165: In Node
osv·2025-05-19·CVSS 3.7
CVE-2025-23165 [LOW] CVE-2025-23165: In Node
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service.
Impact:
* This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.
Red Hat
nodejs: Memory Leak in Node.js ReadFileUtf8 Binding Leading to DoS
vendor_redhat·2025-05-19·CVSS 3.7
CVE-2025-23165 [LOW] CWE-401 nodejs: Memory Leak in Node.js ReadFileUtf8 Binding Leading to DoS
nodejs: Memory Leak in Node.js ReadFileUtf8 Binding Leading to DoS
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service.
Impact:
* This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.
A flaw was found in the ReadFileUtf8 internal binding of Node.js. This vulnerability can allow an attacker to cause an application denial of service via repeated file read operations that trigger an unrecoverable memory leak due to a corrupted pointer in the underlying file system
Debian
CVE-2025-23165: nodejs - In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted ...
vendor_debian·2025·CVSS 3.7
CVE-2025-23165 [LOW] CVE-2025-23165: nodejs - In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted ...
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service. Impact: * This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 20.19.2+dfsg-1)
sid: resolved (fixed in 20.19.2+dfsg-1)
trixie: resolved (fixed in 20.19.2+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-19
Published