ox is vulnerable to Stack-based Buffer Overflow
71
High Risk
This release hardens the ox XML/SAX C parser against stack and dynamic-stack buffer overflow conditions triggered by truncated/unterminated input. The fix adds correct EOS/NULL termination handling, safe pointer/index adjustments before error reporting, and a buffer shift-type correction to prevent overflow/underflow behavior in SAX buffering logic.
You are affected if you are using a version that falls within the vulnerable range.
ox is vulnerable to Stack-based Buffer Overflow in versions 1.0.0 - 2.14.25.
Upgrade the ox library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant