Security Advisory
CVE-2026-58045
6.2
MEDIUM
Vulnerability Description
A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.
Repeated exploitation of this condition can result in a denial of service.
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Published Date
August 4, 2026
Official Source
NIST NVD Advisory