CVE-2025-25283
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Feb 12, 2025
CWE ID 1333
Summary
CVE-2025-25283 is a vulnerability affecting the parse-duraton software, which converts human-readable durations to milliseconds. The issue lies in the CPU-bound operation of resolving durations, leading to event loop delays of up to 50ms and variable memory usage from 0.01 MB to 4.3 MB. Severely impacted versions, prior to 2.1.3, may crash Node.js applications due to an out-of-memory condition from a string size of approximately 10 MB that utilizes unicode characters. Version 2.1.3 includes a patch to address this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share