Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.
References
Configurations
No configuration.
History
04 Nov 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
04 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2024-09-07 16:15
Updated : 2025-11-04 19:16
NVD link : CVE-2023-46809
Mitre link : CVE-2023-46809
CVE.ORG link : CVE-2023-46809
JSON object : View
Products Affected
No product.
CWE
CWE-385
Covert Timing Channel
