cbcvebase.
CVE-2026-58042
published 2026-08-04

CVE-2026-58042: A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering of this…

PriorityP429medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
0.46%
38.2th percentile
A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering of this condition can lead to denial of service. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

Affected

5 ranges
VendorProductVersion rangeFixed in
nodejsnode22.23.1 – 22.23.1
nodejsnode24.18.0 – 24.18.0
nodejsnode26.5.0 – 26.5.0
nodejs_22nodejs
nodejs_24nodejs

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.