Medium severity6.5NVD Advisory· Published Dec 3, 2020· Updated Jun 17, 2026
CVE-2018-21270
CVE-2018-21270
Description
Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
stringstreamnpm | < 0.0.6 | 0.0.6 |
Affected products
3- Node.js/stringstreamdescription
Patches
Vulnerability mechanics
References
5- hackerone.com/reports/321670nvdExploitThird Party AdvisoryWEB
- www.npmjs.com/advisories/664nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-mf6x-7mm4-x2g7ghsaADVISORY
- github.com/mhart/StringStream/issues/7nvdIssue TrackingThird Party Advisory
- github.com/mhart/StringStream/blob/v0.0.5/stringstream.jsghsaWEB
News mentions
0No linked articles in our index yet.