216.73.217.22

CVE-2026-34781

· Published 07/04/2026 22:16 · Modified 08/04/2026 21:27

Labels: CVE-2026-34781 2026-04-07CVE-2026-34781CWE-476[email protected]

Essential information

Published
07/04/2026 22:16
Modified
08/04/2026 21:27
Author
Creator
CVSS
2.8 LOW (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L

CVSS metrics

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that call clipboard.readImage() may be vulnerable to a denial of service. If the system clipboard contains image data that fails to decode, the resulting null bitmap is passed unchecked to image construction, triggering a controlled abort and crashing the process. Apps are only affected if they call clipboard.readImage(). Apps that do not read images from the clipboard are not affected. This issue does not allow memory corruption or code execution. This vulnerability is fixed in 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
electron / Electron cpe:2.3:a:electron:Electron:39.8.5:*:*:*:*:*:*:*
electron / Electron cpe:2.3:a:electron:Electron:40.8.5:*:*:*:*:*:*:*
electron / Electron cpe:2.3:a:electron:Electron:41.1.0:*:*:*:*:*:*:*
electron / Electron cpe:2.3:a:electron:Electron:42.0.0-alpha.5:*:*:*:*:*:*:*

References