CVE-2026-54257

CRITICAL

Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

Title source: cna
STIX 2.1

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 until 42.3.3, Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow. Most apps will crash and some may perform incorrect buffer allocations in the Node.js Buffer API resulting in unexpected truncation or allocation. This vulnerability is fixed in 42.3.3.

References (1)

Core 1
Core References

Scores

CVSS v4 9.3
EPSS 0.0025
EPSS Percentile 16.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-120
Status published
Products (2)
electron/electron >= 42.3.1, < 42.3.3
npm/electron 42.3.1 - 42.3.3npm
Published Jun 23, 2026
Tracked Since Jun 23, 2026