Node.js has released updates to resolve a critical security issue that affects “ almost every production Node.js app” and , if successfully exploited, could cause a denial-of-service (DoS) situation.

“Node.js/V8 makes every effort to recover from stack space exhaustion with a catchable error, which platforms have relied on for service availability,” said Matteo Collina and Joyee Cheung of Node.js.
See also: Serious bug in Broadcom software allows WiFi denial of service
Node.js: How the vulnerability works
The issue arises from the fact that Node.js exits with code 7 (which indicates Internal Exception Handler Run-Time Failure) instead of gracefully handling the exception when a stack overflow in user code while async_hooks is enabled. async_hooks is a low-level Node.js API that allows developers to monitor the lifecycle of asynchronous resources, such as database queries, timers, or HTTP requests.
The issue affects several frameworks and Application Performance Monitoring (APM) tools, including React Server Components, Next.js, Datadog, New Relic, Dynatrace, Elastic APM, and OpenTelemetry. This is due to the use of AsyncLocalStorage, a component built on top of the async_hooks module that enables data to be stored throughout the duration of an asynchronous operation.
See also: Critical vulnerability in ServiceNow allows privilege escalation

The issue affects all versions of Node.js from 8.x to 18.x. It is worth noting that Node.js version 8.0.0, codenamed Carbon, was released on May 30, 2017. However, these versions have not been patched as they have reached their end of life (EoL).
The fixes are included in the following releases:
- Node.js 20.20.0 (LTS)
- Node.js 22.22.0 (LTS)
- Node.js 24.13.0 (LTS)
- Node.js 25.3.0 (Current)
Despite the significant practical impact, Node.js stated that it treats the fix only as a mitigation for a few reasons:
– Stack space exhaustion is not part of the ECMAScript specification.
– The V8 JavaScript engine does not consider this a security issue.
– Limitations with the “uncaughtException” handler, which is designed to be used as a last resort mechanism for exception handling.
See also: CISA: Gogs vulnerability in KEV Catalog

“While this is a fix for undefined behavior, we chose to include it in the security release due to its broad ecosystem impact,” Node.js said. “React Server Components, Next.js, and nearly every APM tool are affected. The fix improves the developer experience and makes error handling more predictable.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Due to the severity of the vulnerability, platform/tool users and server hosting providers are advised to update as soon as possible. Library and platform maintainers are also advised to implement stronger defenses to address stack space exhaustion (to ensure service availability).
