https://seclists.org/oss-sec/2026/q1/63: NodeJS Security leases (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465, and others)
Published Jan 14, 2026
·Updated
Affected Software
1 affected component
npm/node>=20.0.0<=22.999.999, >=22.0.0<=22.999.999, >=24.0.0<=24.999.999
Frequently Asked Questions
1
What is the severity of CVE-2025-59466?
CVE-2025-59466 is classified as a Medium severity vulnerability.
2
How do I fix CVE-2025-59466?
To fix CVE-2025-59466, update your Node.js to the latest version that addresses this issue.
3
What impact does CVE-2025-59466 have on Node.js applications?
CVE-2025-59466 can cause Node.js applications to crash by exceeding the maximum call stack size, bypassing error handlers.
4
What specific error does CVE-2025-59466 relate to in Node.js?
CVE-2025-59466 relates to an uncatchable 'Maximum call stack size exceeded' error in Node.js.
5
When was CVE-2025-59466 published?
CVE-2025-59466 was published on January 14, 2026.