CVE-2025-27209
published 2025-07-18CVE-2025-27209: The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.21%
66.7th percentile
The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an attacker can generate collisions even without knowing the hash-seed. * This vulnerability affects Node.js v24.x users.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | — | — |
| nodejs | node | >= 24.0.0 < 24.4.1 | 24.4.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nodejs: Node.js Rapidhash HashDoS Vulnerability
vendor_redhat·2025-07-18·CVSS 7.5
CVE-2025-27209 [HIGH] CWE-400 nodejs: Node.js Rapidhash HashDoS Vulnerability
nodejs: Node.js Rapidhash HashDoS Vulnerability
The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an attacker can generate collisions even without knowing the hash-seed.
* This vulnerability affects Node.js v24.x users.
A flaw was found in nodejs. The V8 component’s rapidhash implementation introduces a HashDoS vulnerability, allowing an attacker who can control the strings being hashed to trigger excessive CPU usage by generating numerous hash collisions. This exploitation vector results in an application level denial of service condition due to resource exhaustion.
Statement: The severit
Debian
CVE-2025-27209: nodejs - The V8 release used in Node.js v24.0.0 has changed how string hashes are compute...
vendor_debian·2025·CVSS 7.5
CVE-2025-27209 [HIGH] CVE-2025-27209: nodejs - The V8 release used in Node.js v24.0.0 has changed how string hashes are compute...
The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an attacker can generate collisions even without knowing the hash-seed. * This vulnerability affects Node.js v24.x users.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-qr33-gf7m-pq45: The V8 release used in Node
ghsa_unreviewed·2025-07-19
CVE-2025-27209 [HIGH] CWE-407 GHSA-qr33-gf7m-pq45: The V8 release used in Node
The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an attacker can generate collisions even without knowing the hash-seed.
* This vulnerability affects Node.js v24.x users.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-18
Published