PT-2026-2478 · Next.Js+4 · Next.Js+4

Published

2025-01-01

·

Updated

2026-04-01

·

CVE-2025-59466

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Node.js versions 8.x through 18.x Node.js versions 20.x through 20.20.0 Node.js versions 22.x through 22.22.0 Node.js versions 24.x through 24.13.0 Node.js versions 25.x through 25.3.0
Description A critical issue exists in Node.js related to the async hooks module, potentially leading to denial-of-service (DoS) conditions. When async hooks.createHook() is enabled, "Maximum call stack size exceeded" errors become uncatchable, causing the Node.js process to terminate unexpectedly instead of triggering standard error handling mechanisms like process.on('uncaughtException'). This is due to uncontrolled recursion. Applications utilizing AsyncLocalStorage are particularly vulnerable. The vulnerability affects a wide range of frameworks and application performance monitoring (APM) tools. Exploitation of this issue can result in unrecoverable crashes, effectively causing a DoS. The issue impacts nearly every production Node.js application.
Recommendations Update to Node.js version 20.20.0 or later. Update to Node.js version 22.22.0 or later. Update to Node.js version 24.13.0 or later. Update to Node.js version 25.3.0 or later. For versions 8.x through 18.x, update to a supported version.

Fix

DoS

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

ALSA-2026:1842
ALSA-2026:1843
ALSA-2026:2420
ALSA-2026:2421
ALSA-2026:2422
ALSA-2026:2781
ALSA-2026:2782
ALSA-2026:2783
AZL-74973
AZL-74985
BDU:2026-00456
BIT-NODE-2025-59466
BIT-NODE-MIN-2025-59466
CVE-2025-59466
MGASA-2026-0009
OESA-2026-1218
OESA-2026-1219
OESA-2026-1220
OESA-2026-1221
OPENSUSE-SU-2026:10062-1
OPENSUSE-SU-2026:10074-1
OPENSUSE-SU-2026:20236-1
RHSA-2026:1842
RHSA-2026:1843
RHSA-2026:2420
RHSA-2026:2421
RHSA-2026:2422
RHSA-2026:2767
RHSA-2026:2768
RHSA-2026:2781
RHSA-2026:2782
RHSA-2026:2783
RHSA-2026:2864
RHSA-2026:2899
RHSA-2026:6402
RHSA-2026:6431
RHSA-2026:7386
RHSA-2026:7387
SUSE-SU-2026:0295-1
SUSE-SU-2026:0301-1
SUSE-SU-2026:0435-1
SUSE-SU-2026:0457-1
SUSE-SU-2026:20436-1

Affected Products

Next.Js
Node.Js
React Server Components
Red Os
Rocky Linux