CVE-2026-58045 PUBLISHED

Assigner: hackerone
Reserved: 27.06.2026 Published: 04.08.2026 Updated: 04.08.2026

A flaw in Node.js allows a spoofed TypedArray byteLength to trigger a reachable assertion in the synchronous node:zlib APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.

Repeated exploitation of this condition can result in a denial of service.

This vulnerability affects Node.js 22.x, 24.x, and 26.x.

Metrics

CVSS Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 6.2

Product Status

Vendor nodejs
Product node
Versions Default: unaffected
  • affected from 26.5.0 to 26.5.0 (incl.)
  • affected from 24.18.0 to 24.18.0 (incl.)
  • affected from 22.23.1 to 22.23.1 (incl.)

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE