CVE-2026-58045

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
04/08/2026
Last modified:
04/08/2026

Description

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.<br /> <br /> Repeated exploitation of this condition can result in a denial of service.<br /> <br /> This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

References to Advisories, Solutions, and Tools