Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow

Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow

Posted on January 14, 2026January 14, 2026 By CWS

Jan 14, 2026Ravie LakshmananApplication Safety / Vulnerability
Node.js has launched updates to repair what it described as a vital safety challenge impacting “just about each manufacturing Node.js app” that, if efficiently exploited, may set off a denial-of-service (DoS) situation.
“Node.js/V8 makes a best-effort try to get well from stack area exhaustion with a catchable error, which frameworks have come to depend on for service availability,” Node.js’s Matteo Collina and Joyee Cheung stated in a Tuesday bulletin.
“A bug that solely reproduces when async_hooks are used would break this try, inflicting Node.js to exit with 7 straight with out throwing a catchable error when recursions in consumer code exhaust the stack area. This makes functions whose recursion depth is managed by unsanitized enter susceptible to Denial-of-Service assaults.”
At its core, the shortcoming stems from the truth that Node.js exits with code 7 (denoting an Inner Exception Handler Run-Time Failure) as an alternative of gracefully dealing with the exception when a stack overflow happens in consumer code whereas async_hooks is enabled. Async_hooks is a low-level Node.js API that permits builders to trace the lifecycle of asynchronous assets, comparable to database queries, timers, or HTTP requests.

The difficulty, Node.js stated, impacts a number of frameworks and Software Efficiency Monitoring (APM) instruments, together with React Server Elements, Subsequent.js, Datadog, New Relic, Dynatrace, Elastic APM, and OpenTelemetry, owing to using AsyncLocalStorage, a element constructed atop the async_hooks module that makes it attainable to retailer knowledge all through the lifetime of an asynchronous operation.
It has been addressed within the following variations –

Node.js 20.20.0 (LTS)
Node.js 22.22.0 (LTS)
Node.js 24.13.0 (LTS)
Node.js 25.3.0 (Present)

The issue additionally impacts all Node.js variations from 8.x, which was the primary model with async_hooks, to 18.x. It is value noting that Node.js model 8.0.0, codenamed Carbon, was launched on Might 30, 2017. Nonetheless, these variations are unpatched as they’ve reached end-of-life (EoL) standing.
The repair put in place detects stack overflow errors and re-throws them to consumer code as an alternative of treating them as deadly. That is being tracked below the CVE identifier CVE-2025-59466 (CVSS rating: 7.5). Regardless of the numerous sensible affect, Node.js stated it is treating the repair as solely a mitigation owing to a few causes –

“Though it’s a bug repair for an unspecified habits, we selected to incorporate it within the safety launch due to its widespread affect on the ecosystem,” Node.js stated. “React Server Elements, Subsequent.js, and just about each APM instrument are affected. The repair improves developer expertise and makes error dealing with extra predictable.”
In mild of the severity of the vulnerability, customers of the frameworks/instruments and server internet hosting suppliers are beneficial to replace as quickly as attainable. Maintainers of libraries and frameworks are being beneficial to use extra sturdy defenses to counter stack area exhaustion and guarantee service availability.
The disclosure comes as Node.js additionally launched fixes for 3 different high-severity flaws (CVE-2025-55131, CVE-2025-55130, and CVE-2025-59465) that could possibly be exploited to attain knowledge leakage or corruption, learn delicate information utilizing crafted relative symbolic hyperlink (symlink) paths, and set off a distant denial-of-service, respectively.

The Hacker News Tags:async_hooks, Crashes, Critical, Node.js, Overflow, Server, Stack, Vulnerability

Post navigation

Previous Post: 10 Critical Web Injection Attacks in 2026 (Risks & Mitigation)
Next Post: New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages

Related Posts

North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware The Hacker News
Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution The Hacker News
U.K. Police Just Seized £5.5 Billion in Bitcoin — The World’s Largest Crypto Bust U.K. Police Just Seized £5.5 Billion in Bitcoin — The World’s Largest Crypto Bust The Hacker News
Chinese APT41 Exploits Google Calendar for Malware Command-and-Control Operations Chinese APT41 Exploits Google Calendar for Malware Command-and-Control Operations The Hacker News
ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices The Hacker News
LangSmith Bug Could Expose OpenAI Keys and User Data via Malicious Agents LangSmith Bug Could Expose OpenAI Keys and User Data via Malicious Agents The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News