CVE detail
CVE-2021-22918 — CVE-2021-22918
Published 2021-07-12 · Modified 2026-06-17 · Vendor nodejs · Product node.js · Source nvd
MEDIUM
severity
CVSS-derived band
0.2313
EPSS probability
exploitation probability, 30d
98.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References