{"id":"CVE-2026-97058","title":"sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions","summary":"sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision value…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-1284"],"vendor":"alexei","product":"sprintf-js","affected":["sprintf-js <= 1.1.3"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T21:08:22.573","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97058","references":[{"url":"https://github.com/alexei/sprintf.js","label":"disclosure@vulncheck.com"},{"url":"https://github.com/alexei/sprintf.js/blob/3a0d8c26d291b5bd9f1974877ecc50739921d6f5/src/sprintf.js#L17","label":"disclosure@vulncheck.com"},{"url":"https://github.com/alexei/sprintf.js/blob/3a0d8c26d291b5bd9f1974877ecc50739921d6f5/src/sprintf.js#L84-L90","label":"disclosure@vulncheck.com"},{"url":"https://github.com/alexei/sprintf.js/issues/237","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/sprintf-js-through-1.1.3-denial-of-service-via-unbounded-precision","label":"disclosure@vulncheck.com"},{"url":"https://github.com/alexei/sprintf.js/issues/237","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-97058.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-97058"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2540091"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-97058"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97058"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-24T14:32:04.411546Z"},"ingestedAt":"2026-09-24T14:44:21.327Z","slug":"CVE-2026-97058","body":"## Overview\n\nsprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Gatekeeper 3, Migration Toolkit for Applications 8, Multicluster Engine for Kubernetes, Node HealthCheck Operator, OpenShift Pipelines, OpenShift Service Mesh 3, … · no fix planned: Gatekeeper 3, Migration Toolkit for Applications 8, Multicluster Engine for Kubernetes, Node HealthCheck Operator, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-97058.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":210207,"id":"CVE-2026-97058","ts":1790264808841,"field":"exploit_available","old":"false","new":"true"}]}