Denial of Service Vulnerability in Node.js by OpenJS Foundation
CVE-2026-58042

5.9MEDIUM

Key Information:

Vendor

Nodejs

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-58042?

A flaw in Node.js arises from the dns.resolveAny() function, which may cause the Node.js process to abort if a DNS response includes more than 256 address records. This issue can be repeatedly triggered, resulting in denial of service and potentially disrupting service availability for affected users across specific versions of Node.js.

Affected Version(s)

node 26.5.0

node 24.18.0

node 22.23.1

References

CVSS V3.0

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.