VDB

GCVE-VVD-MAGEIA-2021-360

GCVE-VVD-MAGEIA-2021-360
Advisory Published
Vulnetix · Advisory published July 20, 2021
Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo(). (CVE-2021-22918).

Affected Products

VendorProductVersionsPlatforms
Mageialibuv0 (affected), 1.40.0-1.1.mga8 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›