CVE-2023-26109: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
(updated )
All versions of the package node-bluetooth-serial-port is vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.
References
Detect and mitigate CVE-2023-26109 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →