CVE-2018-3745: Atob Project Atob

Critical severity, CVSS 9.1. EPSS: 2.1% chance of exploitation in the next 30 days.

atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.

Affected products

Published 2018-05-29. Last modified 2026-06-17.