CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-23167

mediumcovered by 1 sourcefirst seen 2026-08-03
A local attacker can exploit multiple vulnerabilities in Node.js to conduct a denial of service attack or bypass security measures.

CSIRTS triage

What
Multiple vulnerabilities in Node.js enable denial of service and security measure bypass.
Who is affected
Local users and network actors depending on the vulnerability scope in Node.js deployments are affected.
Urgency
Medium severity; exploitation details depend on specific vulnerability type.
Action
Update Node.js to a patched version addressing CVE-2025-23165, CVE-2025-23166, and CVE-2025-23167.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2025-23167

Get an email if CVE-2025-23167 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2025-23167

CVE.org record

Embed the live status

CVE-2025-23167 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-23167 status](https://www.csirts.com/badge/CVE-2025-23167)](https://www.csirts.com/cve/CVE-2025-23167)