Cyber Resilience

CVE-2023-30588

Nodejs Node.Js 16.0.0 – 16.20.1

Published
28 November 2023
Modified
03 November 2025
Patch / advisory
CVSS Score v3.1 5.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score 0.012 64th percentile
Risk Priority 47 floored blend · peak EPSS

Summary

CVE-2023-30588 is a medium-severity an unspecified weakness vulnerability in Nodejs Node.Js. Its CVSS base score is 5.3 (Medium).

Operationally, ranked in the top 36% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect termination occurs making it susceptible to DoS attacks when the attacker could force interruptions of application processing, as the process terminates when…

more

accessing public key info of provided certificates from user code. The current context of the users will be gone, and that will cause a DoS scenario. This vulnerability affects all active Node.js versions v16, v18, and, v20.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-59466Same product: Nodejs Node.Js
CVE-2026-48928Same product: Nodejs Node.Js
CVE-2026-48933Same product: Nodejs Node.Js
CVE-2026-48936Same product: Nodejs Node.Js
CVE-2024-21890Same product: Nodejs Node.Js
CVE-2026-21636Same product: Nodejs Node.Js
CVE-2023-23918Same product: Nodejs Node.Js
CVE-2025-59464Same product: Nodejs Node.Js
CVE-2023-23919Same product: Nodejs Node.Js
CVE-2023-32002Same product: Nodejs Node.Js

Affected Assets

nodejs
node.js
16.0.0 — 16.20.1 · 18.0.0 — 18.16.1 · 20.0.0 — 20.3.1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References