CVE-2024-38372

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-38372
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-38372.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-38372
Aliases
Downstream
Published
2024-07-08T20:25:59Z
Modified
2025-10-22T18:42:46.992362Z
Severity
  • 2.0 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Undici vulnerable to data leak when using response.arrayBuffer()
Details

Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a fetch() request, response.arrayBuffer() might include portion of memory from the Node.js process. This has been patched in v6.19.2.

Database specific
{
    "cwe_ids": [
        "CWE-201"
    ]
}
References

Affected packages

Git / github.com/nodejs/undici

Affected ranges

Type
GIT
Repo
https://github.com/nodejs/undici
Events

Affected versions

v6.*

v6.14.0
v6.14.1
v6.15.0
v6.16.0
v6.16.1
v6.17.0
v6.18.0
v6.18.1
v6.18.2
v6.19.0
v6.19.1