Low severity3.1NVD Advisory· Published Dec 11, 2017· Updated May 13, 2026
CVE-2017-15897
CVE-2017-15897
Description
Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to all zeros in these cases.
Affected products
1- The Node.js Project/Node.jsv5Range: 8.0 and higher
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- nodejs.org/en/blog/vulnerability/december-2017-security-releases/nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.