Vulnerabilities/

OpenCC has an Out-of-bounds read when processing truncated UTF-8 input

Severity:
Medium

Description

OpenCC versions before 1.2.0 contain two CWE-125: Out-of-bounds Read issues caused by length validation failures in UTF-8 processing. When handling malformed or truncated UTF-8 input, OpenCC trusted derived length values without enforcing the invariant that processed length must not exceed the remaining input buffer.

Recommendation

Update the opencc package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
opencc
Anything's wrong? Let us know Last updated on March 29, 2026