CVE-2026-58042 PUBLISHED

Assigner: hackerone
Reserved: 27.06.2026 Published: 04.08.2026 Updated: 04.08.2026

A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records.

Repeated triggering of this condition can lead to denial of service.

This vulnerability affects Node.js 26.x, 24.x, and 22.x.

Metrics

CVSS Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 5.9

Product Status

Vendor nodejs
Product node
Versions Default: unaffected
  • affected from 26.5.0 to 26.5.0 (incl.)
  • affected from 24.18.0 to 24.18.0 (incl.)
  • affected from 22.23.1 to 22.23.1 (incl.)

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE