A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.
Repeated exploitation of this condition can result in a denial of service.
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-04 01:16
Updated : 2026-09-03 17:02
NVD link : CVE-2026-58045
Mitre link : CVE-2026-58045
CVE.ORG link : CVE-2026-58045
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption
