What is CVE-2026-58042?
CVE-2026-58042 is a flaw in Node.js where the **dns.resolveAny()** function aborts the process when a DNS response contains more than 256 A records. Repeated exploitation can lead to a **Denial of Service (DoS)** condition, affecting Node.js versions **26.x, 24.x and 22.x**, and administrators should apply security updates.
Azərbaycanca: CVE-2026-58042, Node.js-in **dns.resolveAny()** funksiyasında qüsurdur. DNS cavabında 256-dan çox A qeydi olduqda, Node.js prosesi gözlənilmədən dayanır və bu, təkrar istismar zamanı **Denial of Service (DoS)** vəziyyətinə səbəb olur. Təsirə məruz qalan versiyalar **26.x, 24.x və 22.x**-dir, administratorlar Node.js-i təhlükəsiz versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which versions of Node.js are affected by CVE-2026-58042?
This vulnerability affects Node.js versions 26.x, 24.x, and 22.x.
What can CVE-2026-58042 lead to when exploited repeatedly?
Repeated exploitation can lead to a Denial of Service (DoS) condition.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.