PT-2026-67577 · Openjs Foundation · Node.Js
CVE-2026-58045
·
Published
2026-08-01
·
Updated
2026-09-03
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Node.js versions 22.x
Node.js versions 24.x
Node.js versions 26.x
Description
A flaw in the synchronous
node:zlib APIs allows a spoofed byteLength of a TypedArray to trigger a reachable assertion, leading to a process crash. This issue affects all 11 synchronous zlib functions. Repeated exploitation of this condition can result in a denial of service (DoS), which is an attack that makes a system or service unavailable to its intended users.Recommendations
Update Node.js 22.x to the latest patched version.
Update Node.js 24.x to version 24.18.1-1.1 or newer.
Update Node.js 26.x to version 26.5.1-1.1 or newer.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Node.Js