CVE-2026-34776
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on macOS and Linux, apps that call app.requestSingleInstanceLock() were vulnerable to an out-of-bounds heap read when parsing a crafted second-instance message. Leaked memory could be delivered to the app's second-instance event handler. This issue is limited to processes running as the same user as the Electron app. Apps that do not call app.requestSingleInstanceLock() are not affected. Windows is not affected by this issue. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 13
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-125
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-34776",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-34776",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-04-06T15:31:24.470937Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "electron",
"product": "electron",
"versions": [
{
"status": "affected",
"version": "< 38.8.6"
},
{
"status": "affected",
"version": ">= 39.0.0-alpha.1, < 39.8.1"
},
{
"status": "affected",
"version": ">= 40.0.0-alpha.1, < 40.8.1"
},
{
"status": "affected",
"version": ">= 41.0.0-alpha.1, < 41.0.0"
}
]
}
]
}
],
"published": "2026-04-04T00:16:18.753",
"references": [
{
"url": "https://github.com/electron/electron/security/advisories/GHSA-3c8v-cfp5-9885",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on macOS and Linux, apps that call app.requestSingleInstanceLock() were vulnerable to an out-of-bounds heap read when parsing a crafted second-instance message. Leaked memory could be delivered to the app's second-instance event handler. This issue is limited to processes running as the same user as the Electron app. Apps that do not call app.requestSingleInstanceLock() are not affected. Windows is not affected by this issue. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0."
},
{
"lang": "es",
"value": "Electron es un framework para escribir aplicaciones de escritorio multiplataforma usando JavaScript, HTML y CSS. Antes de las versiones 38.8.6, 39.8.1, 40.8.1 y 41.0.0, en macOS y Linux, las aplicaciones que llaman a app.requestSingleInstanceLock() eran vulnerables a una lectura de heap fuera de límites al analizar un mensaje de segunda instancia manipulado. La memoria filtrada podría ser entregada al gestor de eventos de segunda instancia de la aplicación. Este problema se limita a procesos que se ejecutan como el mismo usuario que la aplicación Electron. Las aplicaciones que no llaman a app.requestSingleInstanceLock() no se ven afectadas. Windows no se ve afectado por este problema. Este problema ha sido parcheado en las versiones 38.8.6, 39.8.1, 40.8.1 y 41.0.0."
}
],
"lastModified": "2026-07-24T22:10:00.140",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "9CE003A2-03CC-4355-AA17-2CBD204EC6C3",
"versionEndExcluding": "38.8.6"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "8F28D187-306E-4C9D-ADED-56DD79B04AF3",
"versionEndExcluding": "39.8.1",
"versionStartIncluding": "39.0.0"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "A8E19E38-B08F-4075-A564-E14DC3F54078",
"versionEndExcluding": "40.8.1",
"versionStartIncluding": "40.0.0"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha1:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "A20225D6-F435-4D09-962D-B162F521B6AD"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha2:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "33712802-EB60-4E9A-83B8-9F2320B70CB4"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha3:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "9D0A9142-54FE-47BB-9FEB-5E97528E28FE"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha4:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "9E1D191F-DEAE-4DB3-9822-F31AF9FE3BAC"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha5:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "45A8192F-3D2C-4987-9BBE-7ECC3F71965D"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha6:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "EEA1A2E5-03DB-46CB-8427-7F31A8A7CE1C"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta1:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "B2DFCE75-BD3F-4537-B5B8-14097E262EA2"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta2:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "BC346E25-EA43-4615-8CDB-16D15D46E4FF"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta3:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "FA5B3C00-CAFC-4995-BF35-9920F3039E77"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta4:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "3672F3FB-6B5E-40FD-8A92-CB4DD6BC6A93"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta5:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "9EE4F8AE-21D2-4815-85B7-B7ECCC0D5059"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta6:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "D195760C-7DD9-4259-9042-EDE65AEAC1D6"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta7:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "B370859F-24D3-4B25-B580-1A5B6DB94BFE"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta8:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "7F47CFAE-9744-4B54-B7E4-BB8E4346FDBA"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}