CVE-2026-97058
Last modified
CVE-2026-97058 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload..
Description
sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| alexei | sprintf-js | <= 1.1.3 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-97058?
How severe is CVE-2026-97058?
How do I fix CVE-2026-97058?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9702The InPost PL WordPress plugin before 1.9.1 does not verify …7.5
- CVE-2026-9704A flaw was found in Keycloak. An authenticated user with low…8.8
- CVE-2026-9705A flaw was found in Keycloak's client registration service. …6.5
- CVE-2026-97055SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenize…8.1
- CVE-2026-97056SigNoz versions from v0.98.0 up to (but not including) v0.14…6.8
- CVE-2026-97057redis-parser through 3.0.0 fails to validate the multi-bulk …7.5
- CVE-2026-97059DCMTK through 3.7.0 contains a heap over-read vulnerability …8.2
- CVE-2026-97060X-SpringBoot through 6.0 lacks object-level authorization in…7.2
- CVE-2026-97061Black Candy through 3.2.1 fails to scope playlist search que…4.3
- CVE-2026-97062Aureus ERP through 1.6.0 stores uploaded SVG files on its pu…5.4
- CVE-2026-97063X-SpringBoot through 6.0 returns login verification codes in…9.1
- CVE-2026-97064X-SpringBoot through 6.0 ships with a hardcoded static maste…9.1
Are you affected by CVE-2026-97058?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
