Potential Security Vulnerability Detected
Repository: nodejs/node
Commit: 7547e79
Author: Node.js GitHub Bot
Date: 2026-03-20T17:25:46Z
Commit Message
deps: update icu to 78.3
PR-URL: https://github.com/nodejs/node/pull/62324
Reviewed-By: Richard Lau <richard.lau@ibm.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Pull Request
PR: #62324 - deps: update icu to 78.3
Labels: test, tools, i18n-api, author ready, needs-ci, dependencies, icu, lts-watch-v22.x, lts-watch-v24.x
Description:
This is an[ automated update](https://github.com/nodejs/node/actions/runs/23257091672/job/67615018642) of icu to 78.3.
Analysis
Vulnerability Type: Integer Overflow / Division by Zero
Severity: Medium
Description
The patch fixes ICU-23109 in nfrule.cpp where util64_pow(rule1->radix, rule1->exponent) could overflow to zero, causing a subsequent modulo-by-zero operation (rule1->baseValue % util64_pow(rule1->radix, rule1->exponent)). While there was already a comment about preventing % 0, the existing check rule1->radix != 0 did not guard against the case where the power computation itself overflows to zero. The patch introduces a pre-computed mod variable with an explicit overflow check, returning an error status if mod is zero.
Affected Code
if ((rule1->baseValue > 0
&& (rule1->radix != 0) // ICU-23109 Ensure next line won't "% 0"
&& (rule1->baseValue % util64_pow(rule1->radix, rule1->exponent)) == 0)
Proof of Concept
Construct an ICU RuleBasedNumberFormat rule with a large radix and exponent such that util64_pow(radix, exponent) overflows uint64_t to 0, e.g., radix=10, exponent=20+ causes overflow. This triggers division-by-zero in the modulo operation `rule1->baseValue % 0`, which is undefined behavior in C++ and can cause a crash (SIGFPE or abort) when parsing/formatting numbers with such rules in Node.js via the Intl API.
This issue was automatically created by Vulnerability Spoiler Alert.
Detected at: 2026-03-20T17:43:15.359Z
Potential Security Vulnerability Detected
Repository: nodejs/node
Commit: 7547e79
Author: Node.js GitHub Bot
Date: 2026-03-20T17:25:46Z
Commit Message
Pull Request
PR: #62324 - deps: update icu to 78.3
Labels: test, tools, i18n-api, author ready, needs-ci, dependencies, icu, lts-watch-v22.x, lts-watch-v24.x
Description:
This is an[ automated update](https://github.com/nodejs/node/actions/runs/23257091672/job/67615018642) of icu to 78.3.
Analysis
Vulnerability Type: Integer Overflow / Division by Zero
Severity: Medium
Description
The patch fixes ICU-23109 in nfrule.cpp where
util64_pow(rule1->radix, rule1->exponent)could overflow to zero, causing a subsequent modulo-by-zero operation (rule1->baseValue % util64_pow(rule1->radix, rule1->exponent)). While there was already a comment about preventing% 0, the existing checkrule1->radix != 0did not guard against the case where the power computation itself overflows to zero. The patch introduces a pre-computedmodvariable with an explicit overflow check, returning an error status if mod is zero.Affected Code
Proof of Concept
This issue was automatically created by Vulnerability Spoiler Alert.
Detected at: 2026-03-20T17:43:15.359Z