GHSA-27wq-qx3q-fxm9

Suggest an improvement
Source
https://github.com/advisories/GHSA-27wq-qx3q-fxm9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-27wq-qx3q-fxm9/GHSA-27wq-qx3q-fxm9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-27wq-qx3q-fxm9
Aliases
Published
2021-08-23T19:42:28Z
Modified
2026-07-08T06:28:22Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Improper Handling of Unexpected Data Type in ced
Details

Impact

In ced v0.1.0, passing data types other than Buffer causes the Node.js process to crash.

Patches

The problem has been patched in ced v1.0.0. You can upgrade from v0.1.0 without any breaking changes.

Workarounds

Before passing an argument to ced, verify it’s a Buffer using Buffer.isBuffer(obj).

CVSS score

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/RL:O/RC:C

Base Score: 7.5 (High) Temporal Score: 7.2 (High)

Since ced is a library, the scoring is based on the “reasonable worst-case implementation scenario”, namely, accepting data from untrusted sources over a network and passing it directly to ced. Depending on your specific implementation, the vulnerability’s severity in your program may be different.

Proof of concept

const express = require("express");
const bodyParser = require("body-parser");
const ced = require("ced");

const app = express();

app.use(bodyParser.raw());

app.post("/", (req, res) => {
  const encoding = ced(req.body);

  res.end(encoding);
});

app.listen(3000);

curl --request POST --header "Content-Type: text/plain" --data foo http://localhost:3000 crashes the server.

References

Database specific
{
    "cwe_ids":  [
        "CWE-241"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2021-08-23T17:18:32Z",
    "nvd_published_at":  "2021-08-17T23:15:00Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / ced

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-27wq-qx3q-fxm9/GHSA-27wq-qx3q-fxm9.json"