Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Node.js

Node.js Vendor Cyber Rating & Cyber Score

nodejs.org

Node.js is a JavaScript runtime, used worldwide by millions.


Node.js A.I CyberSecurity Scoring

Node.js
Company Information
Website:https://nodejs.org/en/
Employees number:707
Number of followers:398,477
NAICS:5112
Industry Type:Software Development
Homepage:nodejs.org
Node.js Risk Score (AI oriented)
Between 750 and 799
logo
Node.jsSoftware Development
Updated:
31/08/2026
761/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Node.js Global Score (TPRM)
xxxx
logo
Node.jsSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Node.js
Node.jsFair
Current Score
761Baa (FAIR)
01000
2 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
761Before Incident
AUGUST 2026
760Before Incident
JULY 2026
760Before Incident
JUNE 2026
759Before Incident
MAY 2026
759Before Incident
APRIL 2026
759Before Incident
MARCH 2026
758Before Incident
FEBRUARY 2026
758Before Incident
JANUARY 2026
762Before Incident
Vulnerability
14 Jan 2026Node.js
Node.js and Dynatrace: Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow

Node.js Critical Security Issue Leading to Denial-of-Service (DoS)

758After Incident
HIGH-4
NODDYN1768467414
Node.js Patches Critical DoS Vulnerability Affecting Widespread Ecosystem Node.js has released urgent security updates to address a critical denial-of-service (DoS) vulnerability (CVE-2025-59466, CVSS 7.5) that could crash nearly all production Node.js applications if exploited. The flaw arises when stack space exhaustion occurs in user code while the `async_hooks` API is enabled, causing Node.js to exit abruptly with an error code (7) instead of throwing a catchable exception. The issue stems from a bug in Node.js’s handling of stack overflows in conjunction with `async_hooks`, a low-level API used to track asynchronous operations. Frameworks and Application Performance Monitoring (APM) tools including React Server Components, Next.js, Datadog, New Relic, Dynatrace, Elastic APM, and OpenTelemetry are affected due to their reliance on `AsyncLocalStorage`, a component built on `async_hooks`. The vulnerability impacts all Node.js versions from 8.x (released in 2017) through 18.x, though only supported LTS and current releases have received patches. Fixed versions include: - Node.js 20.20.0 (LTS) - Node.js 22.22.0 (LTS) - Node.js 24.13.0 (LTS) - Node.js 25.3.0 (Current) End-of-life (EoL) versions (8.x–18.x) remain unpatched. The fix rethrows stack overflow errors to user code rather than treating them as fatal, improving error handling predictability. Node.js acknowledged the fix as a mitigation, citing limitations in the ECMAScript specification and V8’s stance on stack exhaustion. Alongside this flaw, Node.js patched three additional high-severity vulnerabilities (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465) enabling data leakage, symlink-based file reads, and remote DoS attacks. The updates underscore the need for prompt upgrades in affected environments.
INCIDENT DETAILS -
TYPE
Denial-of-Service (DoS)
IMPACT
Systems Affected: Node.js applications using async_hooks or frameworks/tools relying on AsyncLocalStorageDowntime: Potential service unavailability due to process terminationOperational Impact: Denial-of-service leading to service disruptionBrand Reputation Impact: Potential reputational damage due to service outages
DECEMBER 2025
762Before Incident
NOVEMBER 2025
762Before Incident
OCTOBER 2025
762Before Incident
MAY 2025
763Before Incident
Vulnerability
01 May 2025Node.js
Node.js

TOCTOU Vulnerability in Node.js CI/CD Infrastructure

761After Incident
HIGH-2
NOD600050125
Security researchers discovered a critical TOCTOU vulnerability in Node.js’s CI/CD infrastructure that allowed attackers to execute malicious code on internal Jenkins agents. An adversary could submit a legitimate pull request, obtain approval and the request-ci label, then push new commits with forged timestamps to bypass code review checks. Once inside the pipeline, the malicious payload could establish persistence in the Jenkins environment, harvest internal credentials and move laterally across build and test systems. A parallel flaw in the commit-queue process might have enabled injection of unreviewed code directly into the main branch, threatening the entire Node.js supply chain. The Node.js security team swiftly restricted access to vulnerable Jenkins runs, rebuilt 24 compromised machines, disabled affected GitHub workflows and replaced timestamp validation with SHA-based checks. They also audited 140 Jenkins jobs to remediate gaps. Although no customer data breach was reported, the incident exposed critical internal infrastructure, credentials and trust in the build process, forcing rapid incident response and infrastructure overhaul.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Internal Jenkins agentsBuild and test systems

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Node.js ?
?
What was Node.js's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Node.js's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Node.js's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Node.js's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Node.js's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Node.js's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Node.js's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Node.js's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Node.js's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Node.js's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Node.js's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Node.js's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Node.js ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Node.js's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?