Feed/CVE-2026-54257
CVE-2026-54257CRITICALCVSS 0.0

Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

Published Jun 15, 2026·Updated Jul 20, 2026

NVD Description

### Impact Most apps will crash and some may perform incorrect buffer allocations in the Node.js `Buffer` API resulting in unexpected truncation or allocation. ### Workarounds No workarounds. Do not use these impacted Electron releases ### Fixed Versions * `42.3.3` ### For more information If you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org)

Affected Packages (1)

electronNPM
From 42.3.1
Fixed in 42.3.3

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free