Description
Versions of atob before 2.1.0 uninitialized Buffers when number is passed in input on Node.js 4.x and below.
Recommendation
Update the atob package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.1.0
- Patched version(s): 2.1.0
References
Could your website be exposed too?
SmartScanner can check your website for Out-of-bounds Read in atob and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Open Chinese Convert subject to Denial of Service via Out-of-bounds Read - CVE-2018-16982
- OpenCC has an Out-of-bounds read when processing truncated UTF-8 input - Vulnerability
- Out-of-bounds Read in base64url - Vulnerability
- Open Chinese Convert has Out-of-bounds Write - CVE-2025-15536
You might also like:
See something that needs correcting? Let us knowUpdated June 22, 2023


