Node.js zlib Spoofed TypedArray byteLength Crash (CVE-2026-58045)
CVE-2026-58045 Published on August 4, 2026
A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected. Repeated exploitation of this condition can result in a denial of service. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Weakness Type
What is a Resource Exhaustion Vulnerability?
The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVE-2026-58045 has been classified to as a Resource Exhaustion vulnerability or weakness.
Affected Versions
nodejs node:- Version 26.5.0, <= 26.5.0 is affected.
- Version 24.18.0, <= 24.18.0 is affected.
- Version 22.23.1, <= 22.23.1 is affected.