Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Forge | Digitalbazaar | * | 1.3.2 (excluding) |
| Migration Toolkit for Virtualization 2.9 | RedHat | migration-toolkit-virtualization/mtv-console-plugin-rhel9:sha256:5d385ba67a8d8158790da4511586c190a24a194e2ccb10fcb7182b658a59c624 | * |
| Network Observability (NETOBSERV) 1.11.0 | RedHat | network-observability/network-observability-console-plugin-compat-rhel9:sha256:a9d0f02ab4310c5a2b2026f424a07d35bcd2ab74e5f9fabba10a2514bef29545 | * |
| Network Observability (NETOBSERV) 1.11.0 | RedHat | network-observability/network-observability-console-plugin-rhel9:sha256:77695f611b1122150c84ee648c674037c488007684d8644a5fc420e111e447b1 | * |
| Red Hat Advanced Cluster Security for Kubernetes 4.8 | RedHat | advanced-cluster-security/rhacs-main-rhel8:sha256:fe5172976364ca5ef1bd83d25b5a51497d51782ef30706ccbceae3db64d10019 | * |
| Red Hat Advanced Cluster Security for Kubernetes 4.9 | RedHat | advanced-cluster-security/rhacs-main-rhel8:sha256:1324d938cf5047df9125eb4bf6a9565fc4443b62c24e34494c1f57d1f8b5bdb1 | * |
| Red Hat Advanced Cluster Security for Kubernetes 4.9 | RedHat | advanced-cluster-security/rhacs-main-rhel8:sha256:68ec422055d5c2bd25e891853a5871e57f2c3a175ccea404be52a84c5b470e8f | * |
| Red Hat Ansible Automation Platform 2.6 | RedHat | ansible-automation-platform-26/lightspeed-rhel9:sha256:09874121ddf67363bdbf0e357c9e286551f34196307c13b0b432f7a1b9b3d45f | * |
| Red Hat Ceph Storage 8 | RedHat | rhceph/grafana-rhel9:sha256:b219c4478e43d68d1a3f2bb9aa0ec16cd30d11587d48ab5952ac09b03771c396 | * |
| Red Hat Developer Hub 1.7 | RedHat | rhdh/rhdh-hub-rhel9:sha256:29ada5e84c6b204cf518191a21bbd22de5cb53a61bc1812b1072ce5c28a235b2 | * |
| Red Hat Developer Hub 1.8 | RedHat | rhdh/rhdh-hub-rhel9:sha256:27d08ffa1bc6a2270b5eab59aedaf866cf68ccb902503c2e58e2e2337a1236b9 | * |
| Red Hat Discovery 2 | RedHat | discovery/discovery-ui-rhel9:sha256:8af6fd7c8fe38d6bfd22e42810badde0aeeae738ea28667ae29dbc0cf4266f3e | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:sha256:d8156790f262ad6081b9030afb6516f26079ae11612f6c2e78bc518ea92f10d3 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9:sha256:f648e514b71fef0d52d45e97c765a0fb1ab98d69209b4214aa0100cb1cc02329 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:sha256:b275a657a249223727b565df671c6c0db6e988b267cdb3ba0619c6334718747b | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:sha256:12128f22697ec726d3cfa2b3eee1175976a87c4fab3aa6dcd89d9abe67093d0c | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:sha256:7a884421baef638e002bc0fcecfd46ea42dec4001c558bb1185b8b8363b0adb2 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:sha256:29293cdd2749c301a0e042ae09192e12ac2820cc18a1cfae2604906da61990ca | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:sha256:5cb6f52106f21514649baea4646169c183d6b754397e3611c956aa174f3e5535 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:sha256:b5bfb2913aa76f6d8036eb99b5900bdc0ff191981e9ede1be06c44e150c78502 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:sha256:b21253e4b3674a593883c00064cf789f9af152824cd6bb8dfa7dd64a958871a3 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9:sha256:44c8c2789b1773d6a66d68eac85262ac173989f99ae5bc0ea8c192bd1504d3f2 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9:sha256:a0d1f6b27d2efdeed7e9704b5ebadea84cc57a1b5a43a9288531430f6de0b3f3 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9:sha256:75cb61e92fd90fb9c0dffbda67fd43b089cc2bf39eedcacc5ff09bfd04024c41 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:sha256:f818bea78b6625dd967ef8ea3ef914fdf48f50169e78590ea01d8aad0c9dc3f7 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:sha256:a4e27470683e611f9a48d97ed99223310876c2c9899fc031e3761f436d5822b0 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:sha256:8c992019d49325f304a04bbe85b3b269f31cb86d69c48a05e462521d68242ba3 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:sha256:88a634abd0d43f5d749565f4485fc2dead0b4347744c7553fd9b19a6c7b67fac | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:sha256:fcfb4db43f18461159c3523a989178e34c190f1109f38af0f215017904bdaac8 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:sha256:21ce8b1d704b14c4d0c68fb2cd8db48d9e22e636a060fedc221f00980333de0a | * |
| Red Hat OpenShift Dev Spaces (RHOSDS) 3.26 | RedHat | devspaces/code-rhel9:sha256:772af8d40b674ce306850d3ecf2b70b39bdceaf9e045a2db9299c0dd8bd5e6b5 | * |
| Red Hat OpenShift GitOps 1.18 | RedHat | openshift-gitops-1/console-plugin-rhel8:sha256:67049777e7c82a5e07124c2b00508a2d343146db3126ee013faa9fbc7ea47458 | * |
| Red Hat OpenShift Pipelines 1.15 | RedHat | openshift-pipelines/pipelines-hub-ui-rhel8:sha256:d356f3a86b2d3054a9f9c6e36bd488c8eaaef4af199e6a8188f8b50921698d25 | * |
| Red Hat OpenShift Pipelines 1.15 | RedHat | openshift-pipelines/pipelines-hub-ui-rhel8:sha256:d356f3a86b2d3054a9f9c6e36bd488c8eaaef4af199e6a8188f8b50921698d25 | * |
| Red Hat OpenShift Service Mesh 2.6 | RedHat | openshift-service-mesh/kiali-ossmc-rhel8:sha256:ab2b4a1a2d1e5230e3c092af3827a21c0838702ae227afd786925d1704002afd | * |
| Red Hat OpenShift Service Mesh 2.6 | RedHat | openshift-service-mesh/kiali-rhel8:sha256:add09864ea186e10cbf36efa26c5e2be626c6e2a47726379d209e5a6cc5698fe | * |
| Red Hat OpenShift Service Mesh 3 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:sha256:7e2b22107128f05f40773095ae2b01ae6c65df0539677ea0d5b8f90c7f907f98 | * |
| Red Hat OpenShift Service Mesh 3 | RedHat | openshift-service-mesh/kiali-rhel9:sha256:9ab887b31e9d45ef89acd26b0d2bd9aeb5fc7c87d0f296d605ed9fa5d8c6a50e | * |
| Red Hat OpenShift Service Mesh 3.1 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:sha256:75b9064c9e83a08e0147ff97fd45ca8b3adb6f16bccedf66c146a74a8c769b25 | * |
| Red Hat OpenShift Service Mesh 3.1 | RedHat | openshift-service-mesh/kiali-rhel9:sha256:ef0ddf23bae41b1c9aad0b05c90aecc2a21b45e125013a139e705c27285907c5 | * |
| Red Hat OpenShift Service Mesh 3.2 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:sha256:8075a2d2d3d00efdce0280e00fa2724d339703a236ef7c74e546c4f0ce023d9b | * |
| Red Hat OpenShift Service Mesh 3.2 | RedHat | openshift-service-mesh/kiali-rhel9:sha256:2de7e4731db7bb2181168aba0de859a06ab1ae13ff8c7b175cde337541925c5d | * |
| Red Hat Quay 3.1 | RedHat | quay/quay-rhel8:sha256:5cf58b1f54219b67c725f4a5066d9e757e7b5ece39d5de1a474a8be6a3490401 | * |
| Red Hat Quay 3.12 | RedHat | quay/quay-rhel8:sha256:03a485b1c02f5155f22c7820c166889b3f7d7b479892bb4d106432fa2dbf217b | * |
| Red Hat Quay 3.16 | RedHat | quay/quay-rhel9:sha256:ff78174701ecd4c840dff59667f0790419f850771f6726973434bf5fd6e81687 | * |
| Red Hat Quay 3.9 | RedHat | quay/quay-rhel8:sha256:8bd901f9d03817e599a73b4f4355236320bec1b803bd9507383277f27fde4319 | * |