AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-46809

HIGH · CVSS 7.4 EPSS 1.30%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-09-07 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.4. It affects OpenSSL.

CVE
CVE-2023-46809
Severity
HIGH
CVSS
7.4
EPSS
1.30%
OpenSSL

Original NVD Description

Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.