Weakness
A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Affected products
- nodejs node.js
References
- https://nodejs.org/en/blog/vulnerability/june-2026-security-releases
- https://access.redhat.com/errata/RHSA-2026:28727
- https://access.redhat.com/errata/RHSA-2026:29012
- https://access.redhat.com/errata/RHSA-2026:30172
- https://access.redhat.com/errata/RHSA-2026:35841
- https://access.redhat.com/errata/RHSA-2026:35842
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.