CVE-2014-9748: Libuv
High severity, CVSS 8.1. EPSS: 2.5% chance of exploitation in the next 30 days.
The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent threads from releasing the locks of other threads, which allows attackers to cause a denial of service (deadlock) or possibly have unspecified other impact by leveraging a race condition.
Affected products
- Libuv Libuv: before 1.7.4 (fixed in 1.7.4)
- Node.js Node.js: from 0.10.0, before 0.10.46 (fixed in 0.10.46); from 0.12.0, before 0.12.15 (fixed in 0.12.15)
Published 2020-02-11. Last modified 2026-06-17.