{"id":"CVE-2026-54257","aliases":["GHSA-q6m5-f73j-m9mc"],"title":"Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow","summary":"Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow","severity":"critical","cwe":["CWE-120"],"vendor":"electron","product":"electron","ecosystem":"npm","affected":["electron >= 42.3.1, < 42.3.3"],"patched":["electron 42.3.3"],"published":"2026-06-15","updated":"2026-06-15","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-q6m5-f73j-m9mc","references":[{"url":"https://github.com/electron/electron/security/advisories/GHSA-q6m5-f73j-m9mc"},{"url":"https://github.com/advisories/GHSA-q6m5-f73j-m9mc"}],"tags":["ghsa","npm"],"epss":0.00428,"epssPercentile":0.36534,"ingestedAt":"2026-07-07T15:41:58.654Z","slug":"CVE-2026-54257","body":"## Overview\n\n### Impact\nMost apps will crash and some may perform incorrect buffer allocations in the Node.js `Buffer` API resulting in unexpected truncation or allocation.\n\n### Workarounds\nNo workarounds. Do not use these impacted Electron releases\n\n### Fixed Versions\n* `42.3.3`\n\n### For more information\nIf you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org)\n\n## Affected packages\n\n- `electron >= 42.3.1, < 42.3.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `electron 42.3.3`","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":52.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}