{"id":"GHSA-65ch-62r8-g69g","summary":"node-forge is vulnerable to ASN.1 OID Integer Truncation","details":"### Summary\n\n**MITRE-Formatted CVE Description**\nAn Integer Overflow (CWE-190) vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions.\n\n### Description\n\nAn ASN.1 OID Integer Truncation vulnerability exists in the node-forge `asn1.derToOid` function within `forge/lib/asn1.js`. OID components are decoded using JavaScript's bitwise left-shift operator (`\u003c\u003c`), which forcibly casts values to 32-bit signed integers. Consequently, if an attacker provides a mathematically unique, very large OID arc integer exceeding $2^{31}-1$, the value silently overflows and wraps around rather than throwing an error. \n\n### Impact\n\nThis vulnerability allows a specially crafted ASN.1 object to spoof an OID, where a malicious certificate with a massive, invalid OID is misinterpreted by the library as a trusted, standard OID, potentially bypassing security controls.\n\nThis vulnerability impacts the `asn1.derToOid` function in `node-forge` before patched version `1.3.2`. \n\nAny downstream application using this component is impacted. This component may be leveraged by downstream applications in ways that enables partial compromise of integrity, leading to potential availability and confidentiality compromises.","aliases":["CVE-2025-66030"],"modified":"2026-07-17T21:09:46.788046966Z","published":"2025-11-26T22:07:44Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-11-26T22:07:44Z","nvd_published_at":"2025-11-26T23:15:49Z","cwe_ids":["CWE-190"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/digitalbazaar/forge/security/advisories/GHSA-65ch-62r8-g69g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66030"},{"type":"WEB","url":"https://github.com/digitalbazaar/forge/commit/3e0c35ace169cfca529a3e547a7848dc7bf57fdb"},{"type":"PACKAGE","url":"https://github.com/digitalbazaar/forge"}],"affected":[{"package":{"name":"node-forge","ecosystem":"npm","purl":"pkg:npm/node-forge"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.3.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-65ch-62r8-g69g/GHSA-65ch-62r8-g69g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}