GHSA-8w4h-3cm3-2pm2
GitHub Security Advisory
Out-of-bounds Read in atob
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
Versions of `atob` before 2.1.0 uninitialized Buffers when number is passed in input on Node.js 4.x and below.
## Recommendation
Update to version 2.1.0 or later.
Affected Packages
npm
atob
Affected versions:
0
(fixed in 2.1.0)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: November 25, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.