Critical severityGHSA Advisory· Published Jun 15, 2026· Updated Jun 15, 2026
Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
CVE-2026-54257
Description
Impact
Most apps will crash and some may perform incorrect buffer allocations in the Node.js Buffer API resulting in unexpected truncation or allocation.
Workarounds
No workarounds. Do not use these impacted Electron releases
Fixed
Versions * 42.3.3
For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
electronnpm | >= 42.3.1, < 42.3.3 | 42.3.3 |
Affected products
2- Range: >= 42.3.1, < 42.3.3
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.