CVE Vulnerabilities

CVE-2025-12816

Interpretation Conflict

Published: Nov 25, 2025 | Modified: Jan 02, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.7 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.

Weakness

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B’s state.

Affected Software

NameVendorStart VersionEnd Version
ForgeDigitalbazaar*1.3.1 (including)
Migration Toolkit for Virtualization 2.9RedHatmigration-toolkit-virtualization/mtv-console-plugin-rhel9:sha256:5d385ba67a8d8158790da4511586c190a24a194e2ccb10fcb7182b658a59c624*
Red Hat Advanced Cluster Security 4.8RedHatadvanced-cluster-security/rhacs-main-rhel8:sha256:438b4904d97ca6cd51284955f284c0b078af30859460eb1ed608e20535ccc2c8*
Red Hat Developer Hub 1.7RedHatrhdh/rhdh-hub-rhel9:sha256:29ada5e84c6b204cf518191a21bbd22de5cb53a61bc1812b1072ce5c28a235b2*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:sha256:8af6fd7c8fe38d6bfd22e42810badde0aeeae738ea28667ae29dbc0cf4266f3e*
Red Hat OpenShift Service Mesh 2.6RedHatopenshift-service-mesh/kiali-ossmc-rhel8:sha256:c34b5d86b07705fd0d610ba37bb54a5612b6aba81f04e661b207a2eb0209bea2*
Red Hat OpenShift Service Mesh 2.6RedHatopenshift-service-mesh/kiali-rhel8:sha256:5fa584e152eb852c9f9dd2ec07c4857924a87470bb92934cbd48efdb0ca238ba*
Red Hat OpenShift Service Mesh 3.0RedHatopenshift-service-mesh/kiali-ossmc-rhel9:sha256:284ba4bea2d340c325d183b866efb72527d297ab6c866b7b18c9e82af43d6af3*
Red Hat OpenShift Service Mesh 3.0RedHatopenshift-service-mesh/kiali-rhel9:sha256:c012e5fdf21c90d8d504164ddec9b294c5c347df078049fcd4e20a9ebe2f76cc*
Red Hat OpenShift Service Mesh 3.1RedHatopenshift-service-mesh/kiali-ossmc-rhel9:sha256:502dcba52460677c5d20f2649216e62c426acb83fbfb38bd630e942b9c0c2733*
Red Hat OpenShift Service Mesh 3.1RedHatopenshift-service-mesh/kiali-rhel9:sha256:9d884a817a1a1e8924b6405e694ffae05f78664f4e00f355ec2ddd7c05446e53*
Red Hat OpenShift Service Mesh 3.2RedHatopenshift-service-mesh/kiali-ossmc-rhel9:sha256:7d670f57a84d17b7be55c897a286654b44f75abeafd81669f89467320018b4ef*
Red Hat OpenShift Service Mesh 3.2RedHatopenshift-service-mesh/kiali-rhel9:sha256:04c798a54632613681f4ff9d07b88b79722dba1cdba1a6e8166ec94a252a81e6*
Red Hat Quay 3.16RedHatquay/quay-rhel9:sha256:ff78174701ecd4c840dff59667f0790419f850771f6726973434bf5fd6e81687*

References