Loading HuntDB...

GHSA-x3cj-3539-rcpx

GitHub Security Advisory

Out-of-Bounds Read in Node.js

⚠ Unreviewed HIGH Has CVE

Advisory Details

Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().

Related CVEs

Key Information

GHSA ID
GHSA-x3cj-3539-rcpx
Published
July 13, 2021 9:07 PM
Last Modified
December 3, 2021 9:04 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 1, 2025 6:44 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.