VDB

ALPINE-CVE-2020-8252

ALPINE-CVE-2020-8252 PUBLISHED CVSS 7.800000190734863 HIGH

The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes.

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.21libuv0, 1.9.1-r0, 1.9.0-r0
Alpine:v3.19nodejs0, 8.9.4-r0, 8.9.3-r1
Alpine:v3.13nodejs12.16.2-r0, 8.11.1-r2, 8.9.4-r0
Alpine:v3.17libuv1.13.1-r0, 1.15.0-r0, 0.10.29-r0
Alpine:v3.21nodejs0, 0, 0
Alpine:v3.15libuv1.32.0-r0, 1.28.0-r0, 1.26.0-r0
Alpine:v3.12nodejs8.9.3-r1, 8.9.4-r0, 8.9.3-r1
Alpine:v3.23libuv1.17.0-r0, 1.4.2-r0, 1.5.0-r0
Alpine:v3.18nodejs8.9.4-r0, 8.9.3-r0, 8.9.2-r0
Alpine:v3.19libuv1.36.0-r0, 1.34.2-r0, 1.34.1-r0
Alpine:v3.13libuv1.9.1-r0, 1.20.2-r0, 0
Alpine:v3.18libuv1.9.1-r0, 1.36.0-r0, 1.34.2-r0
Alpine:v3.20libuv1.34.0-r0, 1.34.1-r0, 1.34.2-r0
Alpine:v3.12libuv1.19.2-r0, 0, 0.10.25-r0
Alpine:v3.20nodejs10.14.1-r0, 10.15.1-r0, 10.15.3-r0
Alpine:v3.16nodejs8.11.2-r0, 8.11.3-r3, 8.11.3-r2
Alpine:v3.22libuv1.11.0-r0, 1.11.0-r1, 1.13.1-r0
Alpine:v3.11nodejs8.11.3-r0, 8.9.4-r0, 8.9.3-r1
Alpine:v3.14libuv1.30.1-r0, 1.22.0-r0, 1.7.5-r0
Alpine:v3.22nodejs0, 0, 0

…and 5 more

Timeline

  • Sep 18, 2020 CVE Published
  • Dec 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›