Denial of Service Vulnerability in Node.js Zlib APIs
CVE-2026-58045

6.2MEDIUM

Key Information:

Vendor

Nodejs

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-58045?

A vulnerability in Node.js has been identified that affects the synchronous zlib APIs, where a manipulated TypedArray's byteLength can lead to a triggering of an assertion. This can cause the entire Node.js process to crash. All synchronous zlib functions are susceptible to this issue, and exploitation can result in a repeated denial of service condition. Node.js versions 22.x, 24.x, and 26.x are affected.

Affected Version(s)

node 26.5.0

node 24.18.0

node 22.23.1

References

CVSS V3.0

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.