
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-58045 is a denial-of-service vulnerability in Node.js's synchronous node:zlib APIs caused by a spoofed TypedArray byteLength triggering a reachable assertion, which crashes the process. It was disclosed on July 29, 2026, as part of Node.js's July 2026 security release batch. The vulnerability affects all active Node.js release lines: 22.x, 24.x, and 26.x. It carries a Medium severity rating, with a CVSS category estimate of Medium (Node.js Advisory).
The root cause is improper handling of a spoofed byteLength property on a TypedArray object passed to the synchronous node:zlib APIs (e.g., zlib.deflateSync(), zlib.inflateSync()). When the reported byteLength does not match the actual buffer size, the zlib binding triggers a reachable assertion failure, causing the Node.js process to abort. This is consistent with CWE-617 (Reachable Assertion) or CWE-787 (Out-of-Bounds Write), as the Feedly description references an out-of-bounds write buffer condition. The vulnerability was reported by researcher byvini and fixed by RafaelGSS (Node.js Advisory).
Successful exploitation causes the Node.js process to crash, resulting in a denial of service. Any application that passes user-controlled or externally influenced TypedArray objects to synchronous node:zlib APIs is at risk. Repeated triggering of this condition can sustain a denial-of-service condition against affected services. There is no known confidentiality or integrity impact beyond process availability (Node.js Advisory).
node:zlib APIs such as zlib.deflateSync(), zlib.inflateSync(), zlib.brotliCompressSync(), or similar.Uint8Array) with a spoofed byteLength property — overriding the getter to return a value inconsistent with the actual underlying buffer size.byteLength, attempts an out-of-bounds operation, hits a reachable assertion, and aborts the Node.js process, causing a denial of service.Assertion failed, node: ../src/... stack traces related to zlib bindings).Node.js has released patched versions addressing CVE-2026-58045: v22.23.2, v24.18.1, and v26.5.1. All users on active release lines (22.x, 24.x, 26.x) should upgrade to the respective patched version immediately. As a workaround, applications can validate TypedArray inputs before passing them to synchronous node:zlib APIs, ensuring the byteLength is consistent with the actual buffer. End-of-Life Node.js versions are also affected and should be migrated to a supported release line (Node.js Advisory, Node.js v22.23.2, Node.js v24.18.1, Node.js v26.5.1).
Security news outlets including CyberSecurityNews and CyberPress covered the broader July 2026 Node.js security release, noting that 11 vulnerabilities were patched across active release lines (CyberSecurityNews, CyberPress). The Apereo CAS project also responded quickly with a dependency update commit referencing the Node.js security releases (Apereo CAS). Community reaction has been moderate, with the focus primarily on the higher-severity HTTP/2 and Permission Model issues in the same release batch.
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"