CVE-2026-58045

Updated on 04 Aug 2026

Severity

6.2 Medium severity

Details

CVSS score
6.2
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

A flaw in Node.js allows a spoofed TypedArray byteLength to trigger a reachable assertion in the synchronous node:zlib APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.

Repeated exploitation of this condition can result in a denial of service.

This vulnerability affects Node.js 22.x, 24.x, and 26.x.

Details

Affected packages:
alt-nodejs12 @ 12 (+92 more)

Fixes