CVE-2026-58045: Node.js Node
Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected. Repeated exploitation of this condition can result in a denial of service. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Affected products
- Node.js Node: from 26, up to and including 26.5.0; from 24, up to and including 24.18.0; from 22, up to and including 22.23.1
Published 2026-08-04. Last modified 2026-09-03.