A vulnerability, which was classified as problematic, has been found in Node.js 22.x/24.x/26.x. The affected element is an unknown function of the component node:zlib. Performing a manipulation of the argument byteLength results in denial of service.

This vulnerability was named CVE-2026-58045. The attack may be initiated remotely. There is no available exploit.