OpenCC has an Out-of-bounds read when processing truncated UTF-8 input
- Severity:
- Medium
Description
OpenCC versions before 1.2.0 contain two CWE-125: Out-of-bounds Read issues caused by length validation failures in UTF-8 processing. When handling malformed or truncated UTF-8 input, OpenCC trusted derived length values without enforcing the invariant that processed length must not exceed the remaining input buffer.
Recommendation
Update the opencc package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.2.0
- Patched version(s): 1.2.0
References
Related Issues
- Open Chinese Convert has Out-of-bounds Write - CVE-2025-15536
- Out-of-bounds Read in base64url - Vulnerability
- Open Chinese Convert subject to Denial of Service via Out-of-bounds Read - CVE-2018-16982
- Out-of-bounds Read in atob - CVE-2018-3745
You might also like:
- Tags:
- npm
- opencc
Anything's wrong? Let us know Last updated on March 29, 2026


