CVE-2026-58045

MEDIUM

Node - Uncontrolled Resource Consumption

Title source: rule
STIX 2.1

Description

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected. Repeated exploitation of this condition can result in a denial of service. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

Scores

CVSS v3 6.2
EPSS 0.0019
EPSS Percentile 8.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (3)
nodejs/node 22.23.1
nodejs/node 24.18.0
nodejs/node 26.5.0
Published Aug 04, 2026
Tracked Since Aug 04, 2026