Security Advisory

CVE-2020-8252

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-09-18 20:11:51
Last updated 2025-04-30 22:24:26
Assigner hackerone
State PUBLISHED

Description

The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes.