{"id":"CVE-2018-7166","details":"In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory. This method is intended to be safe and only return initialized, or cleared, memory. The third argument specifying `encoding` can be passed as a number, this is misinterpreted by `Buffer's` internal \"fill\" method as the `start` to a fill operation. This flaw may be abused where `Buffer.alloc()` arguments are derived from user input to return uncleared memory blocks that may contain sensitive information.","modified":"2026-08-18T11:19:26.758713Z","published":"2018-08-21T12:29:00.320Z","references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2553"},{"type":"ADVISORY","url":"https://nodejs.org/en/blog/vulnerability/august-2018-security-releases/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nodejs/node","events":[{"introduced":"cf41627411886000429bde058a6594fb7f6d6d47"},{"fixed":"03b825811ed4af0addcdf6e75bacb3dc1c4c5940"}],"database_specific":{"cpe":"cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"10.0.0"},{"fixed":"10.9.0"}],"source":"CPE_RANGE"}}],"versions":["v10.8.0","v10.7.0","v10.6.0","v10.5.0","v10.4.1","v10.4.0","v10.3.0","v10.2.1","v10.2.0","v10.1.0","v10.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-7166.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}