CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Critical Node.js async_hooks Stack Overflow Vulnerability

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Node.js has released updates to address a critical vulnerability (CVE-2025-59466) that can cause server crashes via stack overflow in applications using async_hooks. The flaw allows denial-of-service (DoS) attacks when recursion in user code exhausts stack space, affecting multiple frameworks and APM tools. The issue impacts Node.js versions from 8.x to 18.x, though only LTS and current versions have received patches.

Timeline

  1. 14.01.2026 09:05 1 articles · 23h ago

    Node.js Releases Patches for Critical async_hooks Stack Overflow Vulnerability

    Node.js has released updates to address a critical vulnerability (CVE-2025-59466) that can cause server crashes via stack overflow in applications using async_hooks. The flaw affects multiple frameworks and APM tools, with patches available for LTS and current versions. The issue impacts Node.js versions from 8.x to 18.x, though end-of-life versions remain unpatched.

    Show sources

Information Snippets