CVE-2026-54257EPSS p16.7%
CVE-2026-54257CVE-2026-54257
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 until 42.3.3, Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow. Most apps will crash and some may perform incorrect buffer allocations in the Node.js Buffer API resulting in unexpected truncation or allocation. This vulnerability is fixed in 42.3.3.
Scoring
| EPSS | 0.25% probability of exploitation · percentile 16.7% · 2026-08-08T12:02:54Z |
| Last modified | 2026-06-25 |