← back
CVE-2021-22930CWE-416

CVE-2021-22930

15Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 36%
exploitation probability
36%top 2% of all CVEs
observed exploitation
nono source reports it
In short

Node.js versions before 16.6.0, 14.17.4, and 12.22.4 have a memory bug that allows attackers to access memory that has been freed, potentially allowing them to alter how the application behaves.

Technical detail

This is a use-after-free vulnerability (CWE-416) in Node.js where freed memory is accessed, enabling memory corruption. An attacker can exploit this to modify process behavior, though the attack requires specific conditions and the impact depends on the application context.

Summary generated and translated by AI from the official description.
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
Affected products
NodeJS · Node