We found results for “”
CVE-2025-59466
Good to know:
Date: January 20, 2026
We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when "async_hooks.createHook()" is enabled. Instead of reaching "process.on('uncaughtException')", the process terminates, making the crash unrecoverable. Applications that rely on "AsyncLocalStorage" (v22, v20) or "async_hooks.createHook()" (v24, v22, v20) become vulnerable to denial-of-service crashes triggered by deep recursion under specific conditions.
Severity Score
Related Resources (4)
Severity Score
Weakness Type (CWE)
Uncaught Exception
CWE-248Top Fix
Upgrade Version
Upgrade to version https://github.com/nodejs/node.git - v20.20.0;https://github.com/nodejs/node.git - v22.22.0;https://github.com/nodejs/node.git - v24.13.0;https://github.com/nodejs/node.git - v25.3.0
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


