CVE-2020-8252
HIGHlibuv <10.22.1-14.9.0 - Buffer Overflow
Title source: llmDescription
The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes.
References (8)
Scores
CVSS v3
7.8
EPSS
0.0018
EPSS Percentile
39.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-120
Status
published
Affected Products (4)
nodejs/node.js
< 10.22.1
nodejs/node.js
< 14.9.0
opensuse/leap
fedoraproject/fedora
Timeline
Published
Sep 18, 2020
Tracked Since
Feb 18, 2026