Denial of Service Vulnerability in Node.js Zlib APIs
CVE-2026-58045
6.2MEDIUM
What is CVE-2026-58045?
A vulnerability in Node.js has been identified that affects the synchronous zlib APIs, where a manipulated TypedArray's byteLength can lead to a triggering of an assertion. This can cause the entire Node.js process to crash. All synchronous zlib functions are susceptible to this issue, and exploitation can result in a repeated denial of service condition. Node.js versions 22.x, 24.x, and 26.x are affected.
Affected Version(s)
node 26.5.0
node 24.18.0
node 22.23.1
