Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-58045

Опубликовано: 04 авг. 2026
Источник: debian
EPSS Низкий

Описание

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected. Repeated exploitation of this condition can result in a denial of service. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nodejsunfixedpackage

Примечания

  • https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#nodezlib-sync-apis-can-crash-on-spoofed-typedarray-length-cve-2026-58045---medium

EPSS

Процентиль: 9%
0.00189
Низкий

Связанные уязвимости

CVSS3: 6.2
ubuntu
7 дней назад

[Unknown description]

CVSS3: 6.2
nvd
3 дня назад

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected. Repeated exploitation of this condition can result in a denial of service. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

CVSS3: 6.2
github
3 дня назад

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected. Repeated exploitation of this condition can result in a denial of service. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

EPSS

Процентиль: 9%
0.00189
Низкий