CVE-2016-10578: Unicode Project Unicode
High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.
unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.
Affected products
- Unicode Project Unicode: before 9.0.0 (fixed in 9.0.0)
Published 2018-05-29. Last modified 2026-06-17.