CVE-2016-10578

HIGH

Unicode < 9.0.0 - Missing Encryption

Title source: rule
STIX 2.1

Description

unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://nodesecurity.io/advisories/161

Scores

CVSS v3 8.1
EPSS 0.0016
EPSS Percentile 36.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-310 CWE-311
Status published
Products (2)
npm/unicode 0 - 9.0.0npm
unicode_project/unicode < 9.0.0
Published May 29, 2018
Tracked Since Feb 18, 2026