MEDIUM 5.3 Microsoft

CVE-2021-22918

Node.js before 16.4.1 14.17.2 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().

Microsoft Security Update 2021-Jul: Node.js before 16.4.1 14.17.2 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().

Affected Products

References

Published: 2021-07-13 · Source: Microsoft · Feed updated: 2026-10-01
This medium severity vulnerability with a CVSS score of 5.3 was published on 2021-07-13 via Microsoft. EPSS score: 23.1% (top 2% of all CVEs by exploitation probability). Affected: cm1 nodejs 14.17.2-1 on CBL Mariner 1.0, azl3 pytorch 2.2.2-4 on Azure Linux 3.0, azl3 pytorch 2.2.2-7 on Azure Linux 3.0.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.