Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

All disclosures

Vulnerability disclosure

Large DNS responses can abort Node.js workers

CVE-2026-58042

Affected product
Node.js
Severity
Medium · CVSS 5.9
Weakness
CWE-400
Disclosed

Summary

Large DNS responses can abort Node.js workers. This medium-severity finding affects Node.js.

Technical analysis

The accompanying research article explains the finding, reproduction, and remediation status.

Read the technical write-up

Disclosure timeline

Public disclosure

Credits

Cantina · Agent-discovered and human-verified

References