CVE-2026-54257
CRITICALElectron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
Title source: cnaDescription
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 until 42.3.3, Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow. Most apps will crash and some may perform incorrect buffer allocations in the Node.js Buffer API resulting in unexpected truncation or allocation. This vulnerability is fixed in 42.3.3.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/electron/electron/security/advisories/GHSA-q6m5-f73j-m9mc
Scores
CVSS v4
9.3
EPSS
0.0025
EPSS Percentile
16.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-120
Status
published
Products (2)
electron/electron
>= 42.3.1, < 42.3.3
npm/electron
42.3.1 - 42.3.3npm
Published
Jun 23, 2026
Tracked Since
Jun 23, 2026