lmdb is vulnerable to Improper Input Validation
55
Medium Risk
Affected versions of this package bundled a vulnerable LMDB version that could trust malformed on-disk metadata without proper validation, allowing specially crafted data.mdb files from untrusted or tampered sources to trigger process crashes, arbitrary memory reads, heap corruption, NULL dereferences, and other memory-safety failures. An attacker might exploit this by convincing an application to open a malicious LMDB database file, causing denial of service or potentially leveraging the memory corruption conditions to influence process behavior and compromise confidentiality or integrity.
You are affected if you are using a version that falls within the vulnerable range.
lmdb is vulnerable to Improper Input Validation in versions 0.58.0 - 2.0.0.
Upgrade the lmdb library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant