Intel

AIKIDO-2026-10028

node is vulnerable to Use of Uninitialized Resource

Use of Uninitialized ResourceCVE-2025-55131 Published Jan 14, 2026

85

High Risk

This Affects:

OSnode
0.0.1 - 20.19.6
Fixed in 20.20.0
21.0.0 - 22.21.1
Fixed in 22.22.0
23.0.0 - 24.12.0
Fixed in 24.13.0
25.0.0 - 25.2.0
Fixed in 25.3.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package may expose uninitialized memory due to a flaw in Node.js buffer allocation when allocations are interrupted while using the vm module with the timeout option. Under specific timing conditions, buffers created via Buffer.alloc or TypedArray instances such as Uint8Array may contain residual data from previous operations, potentially leaking in-process secrets like tokens or passwords or causing data corruption.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

node is vulnerable to Use of Uninitialized Resource in versions 25.0.0 - 25.2.0, 23.0.0 - 24.12.0, 21.0.0 - 22.21.1 and 0.0.1 - 20.19.6.

How to fix this

Upgrade the node library to a patch version.