CVE-2026-58045
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
04/08/2026
Last modified:
04/08/2026
Description
A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.<br />
<br />
Repeated exploitation of this condition can result in a denial of service.<br />
<br />
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Impact
Base Score 3.x
6.20
Severity 3.x
MEDIUM


