Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4j79-vxj3-vjvm

Опубликовано: 04 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.2

Описание

A flaw in Node.js allows a spoofed TypedArray byteLength to trigger a reachable assertion in the synchronous node:zlib APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.

Repeated exploitation of this condition can result in a denial of service.

This vulnerability affects Node.js 22.x, 24.x, and 26.x.

A flaw in Node.js allows a spoofed TypedArray byteLength to trigger a reachable assertion in the synchronous node:zlib APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.

Repeated exploitation of this condition can result in a denial of service.

This vulnerability affects Node.js 22.x, 24.x, and 26.x.

EPSS

Процентиль: 9%
0.00189
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.2
ubuntu
7 дней назад

[Unknown description]

CVSS3: 6.2
nvd
3 дня назад

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected. Repeated exploitation of this condition can result in a denial of service. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

CVSS3: 6.2
debian
3 дня назад

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigge ...

EPSS

Процентиль: 9%
0.00189
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-400