Intel

AIKIDO-2026-10031

node is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2025-59466 Published Jan 14, 2026

50

Medium Risk

This Affects:

OSnode
0.0.1 - 20.19.6
Fixed in 20.20.0
21.0.0 - 22.21.1
Fixed in 22.22.0
23.0.0 - 24.12.0
Fixed in 24.13.0
25.0.0 - 25.2.0
Fixed in 25.3.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to a crash due to improper error handling when async_hooks.createHook() is enabled. Under specific conditions involving deep recursion, a “Maximum call stack size exceeded” error becomes uncatchable and bypasses process.on('uncaughtException'), causing the Node.js process to terminate unexpectedly. Applications using AsyncLocalStorage or async_hooks.createHook() can therefore be forced into an unrecoverable denial-of-service condition.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

node is vulnerable to Denial of Service (DoS) in versions 25.0.0 - 25.2.0, 23.0.0 - 24.12.0, 21.0.0 - 22.21.1 and 0.0.1 - 20.19.6.

How to fix this

Upgrade the node library to a patch version.