CVE-2026-58045
6.2
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
A flaw in Node.js allows a spoofed TypedArray byteLength to trigger a reachable assertion in the synchronous node:zlib APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.
Repeated exploitation of this condition can result in a denial of service.
This vulnerability affects Node.js 22.x, 24.x, and 26.x.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| nodejs | node | 26.5.0 <= 26.5.0 | affected |
| nodejs | node | 24.18.0 <= 24.18.0 | affected |
| nodejs | node | 22.23.1 <= 22.23.1 | affected |
Weaknesses
- CWE-400: CWE-400 Uncontrolled Resource Consumption
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.