Description
Versions of atob before 2.1.0 uninitialized Buffers when number is passed in input on Node.js 4.x and below.
Recommendation
Update the atob package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.1.0
- Patched version(s): 2.1.0
References
- GHSA-8w4h-3cm3-2pm2
- hackerone.com
- www.npmjs.com
- security.netapp.com
- CVE-2018-3745
- CWE-125
- CAPEC-310
- OWASP 2021-A6
Related Issues
- Open Chinese Convert subject to Denial of Service via Out-of-bounds Read - CVE-2018-16982
- OpenCC has an Out-of-bounds read when processing truncated UTF-8 input - Vulnerability
- Out-of-bounds Read in base64url - Vulnerability
- Open Chinese Convert has Out-of-bounds Write - CVE-2025-15536
You might also like:
- Tags:
- npm
- atob
Anything's wrong? Let us know Last updated on June 22, 2023


