
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-58042 is a denial-of-service vulnerability in Node.js's dns module where dns.resolveAny() can abort the process when a DNS response contains more than 256 A records. Disclosed on July 29, 2026 as part of Node.js's July 2026 security release, it affects all active release lines: 22.x, 24.x, and 26.x. The CVE is currently in "Reserved" status with a CVSS category estimate of Medium severity. The vulnerability was reported by cantina-security and fixed by RafaelGSS (Node.js Advisory).
The root cause lies in improper handling of large DNS responses within Node.js's dns module — specifically, the resolveAny() function fails to correctly process DNS replies containing more than 256 A records, triggering a process abort. This is consistent with CWE-617 (Reachable Assertion) or an unhandled edge case in buffer/array bounds handling during DNS response parsing. An attacker capable of influencing DNS responses seen by a Node.js application (e.g., via a malicious or compromised DNS server, DNS spoofing, or control over a DNS zone) could craft a response with an excessive number of A records to trigger the abort. No preconditions such as authentication are required beyond the ability to influence DNS resolution results for the target application (Node.js Advisory).
Successful exploitation causes the Node.js process to abort (crash), resulting in a denial of service for any application relying on dns.resolveAny(). Repeated triggering of this condition can sustain a denial-of-service condition, making affected services unavailable. There is no known confidentiality or integrity impact — the vulnerability is limited to availability (Node.js Advisory).
dns.resolveAny() for attacker-influenced hostnames or that resolves hostnames via a DNS path the attacker can intercept.resolveAny() query.dns module fails to handle the oversized response, causing the process to abort and resulting in denial of service. Repeat as needed to sustain the outage (Node.js Advisory).journald, syslog) showing abrupt process termination of the Node.js service.Node.js has released patched versions addressing CVE-2026-58042: v22.23.2, v24.18.1, and v26.5.1. All users on active release lines (22.x, 24.x, 26.x) should upgrade to the respective patched version immediately. As a temporary workaround, applications can avoid using dns.resolveAny() or restrict DNS resolution to trusted, controlled resolvers to reduce exposure. End-of-Life Node.js versions are also affected and should be migrated to a supported release line (Node.js Advisory, Node.js v22.23.2, Node.js v24.18.1, Node.js v26.5.1).
The vulnerability was covered by cybersecurity news outlets as part of broader reporting on Node.js's July 2026 security release, which addressed 11 vulnerabilities in total. Coverage highlighted the range of severity levels and the variety of affected subsystems (CyberSecurityNews, Cryptika). No notable individual researcher commentary or significant social media discussion specific to CVE-2026-58042 has been identified beyond general Node.js security release announcements.
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"