Loading HuntDB...

GHSA-f2j2-5fh3-4jrr

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to all zeros in these cases.

Related CVEs

Key Information

GHSA ID
GHSA-f2j2-5fh3-4jrr
Published
May 14, 2022 4:01 AM
Last Modified
April 20, 2025 3:49 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.