unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Unicode |
Unicode_project |
* |
9.0.0 (excluding) |
References