Vulnerability CVE-2022-25872


Published: 2022-06-17

Description:
All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and length calculation for any non-string input as the source. This allows the attacker to read previously allocated memory.

 References:
https://snyk.io/vuln/SNYK-JS-FASTSTRINGSEARCH-2392368
https://github.com/magiclen/node-fast-string-search/blob/c8dd9fc966abc80b327f509e63360f59e0de9fb5/src/fast-string-search.c%23L192

Copyright 2026, cxsecurity.com

 

Back to Top