Denial of Service Vulnerability in Node.js by OpenJS Foundation
CVE-2026-58042
5.9MEDIUM
What is CVE-2026-58042?
A flaw in Node.js arises from the dns.resolveAny() function, which may cause the Node.js process to abort if a DNS response includes more than 256 address records. This issue can be repeatedly triggered, resulting in denial of service and potentially disrupting service availability for affected users across specific versions of Node.js.
Affected Version(s)
node 26.5.0
node 24.18.0
node 22.23.1
