CVE-2025-59466
ADVISORY - nistSummary
We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when async_hooks.createHook() is enabled. Instead of reaching process.on('uncaughtException'), the process terminates, making the crash unrecoverable. Applications that rely on AsyncLocalStorage (v22, v20) or async_hooks.createHook() (v24, v22, v20) become vulnerable to denial-of-service crashes triggered by deep recursion under specific conditions.
Common Weakness Enumeration (CWE)
Uncaught Exception
Allocation of Resources Without Limits or Throttling
Docker
BSA-2025-59466
-
Docker
CVE-2025-59466
-
NIST
3.9
CVSS SCORE
7.5highAlpine
-
Debian
-
Ubuntu
3.9
CVSS SCORE
7.5mediumAlma
-
CVSS SCORE
N/AhighAlma
-
CVSS SCORE
N/AhighAlma
-
CVSS SCORE
N/AhighAlma
-
CVSS SCORE
N/AhighAlma
-
CVSS SCORE
N/AhighAlma
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AhighBitnami
BIT-node-2025-59466
3.9
CVSS SCORE
7.5highBitnami
BIT-node-min-2025-59466
3.9
CVSS SCORE
7.5highRed Hat
2.2
CVSS SCORE
5.9mediumRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighChainguard
CGA-3wxp-gff7-xr5w
-
Photon
CVE-2025-59466
-
CVSS SCORE
7.5highminimos
MINI-27gv-qfg8-mv57
-
minimos
MINI-7wp7-jpwj-rjwh
-
minimos
MINI-9c29-gh9f-mqqf
-
minimos
MINI-cph9-qq2q-vx4q
-
minimos
MINI-hqjc-rx68-3qgr
-
minimos
MINI-vrh8-7xm7-625h
-