Node.js A.I CyberSecurity Scoring
Node.js
Company Information
Website:https://nodejs.org/en/
Employees number:707
Number of followers:398,477
NAICS:5112
Industry Type:Software Development
Homepage:nodejs.org
Node.js Risk Score (AI oriented)
Between 750 and 799
Node.jsSoftware Development
Updated:
31/08/2026
31/08/2026
761/1000
Fair
Baa
Node.js Global Score (TPRM)
xxxx
Node.jsSoftware Development
Score locked

Node.jsFair
Current Score
761Baa (FAIR)
01000
2 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
761
AUGUST 2026
760
JULY 2026
760
JUNE 2026
759
MAY 2026
759
APRIL 2026
759
MARCH 2026
758
FEBRUARY 2026
758
JANUARY 2026
762
Vulnerability
14 Jan 2026 • Node.js
Node.js and Dynatrace: Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow
Node.js Critical Security Issue Leading to Denial-of-Service (DoS)
758
HIGH-4
NODDYN1768467414
Node.js Patches Critical DoS Vulnerability Affecting Widespread Ecosystem
Node.js has released urgent security updates to address a critical denial-of-service (DoS) vulnerability (CVE-2025-59466, CVSS 7.5) that could crash nearly all production Node.js applications if exploited. The flaw arises when stack space exhaustion occurs in user code while the `async_hooks` API is enabled, causing Node.js to exit abruptly with an error code (7) instead of throwing a catchable exception.
The issue stems from a bug in Node.js’s handling of stack overflows in conjunction with `async_hooks`, a low-level API used to track asynchronous operations. Frameworks and Application Performance Monitoring (APM) tools including React Server Components, Next.js, Datadog, New Relic, Dynatrace, Elastic APM, and OpenTelemetry are affected due to their reliance on `AsyncLocalStorage`, a component built on `async_hooks`.
The vulnerability impacts all Node.js versions from 8.x (released in 2017) through 18.x, though only supported LTS and current releases have received patches. Fixed versions include:
- Node.js 20.20.0 (LTS)
- Node.js 22.22.0 (LTS)
- Node.js 24.13.0 (LTS)
- Node.js 25.3.0 (Current)
End-of-life (EoL) versions (8.x–18.x) remain unpatched. The fix rethrows stack overflow errors to user code rather than treating them as fatal, improving error handling predictability. Node.js acknowledged the fix as a mitigation, citing limitations in the ECMAScript specification and V8’s stance on stack exhaustion.
Alongside this flaw, Node.js patched three additional high-severity vulnerabilities (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465) enabling data leakage, symlink-based file reads, and remote DoS attacks. The updates underscore the need for prompt upgrades in affected environments.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
DECEMBER 2025
762
NOVEMBER 2025
762
OCTOBER 2025
762
MAY 2025
763
Vulnerability
01 May 2025 • Node.js
Node.js
TOCTOU Vulnerability in Node.js CI/CD Infrastructure
761
HIGH-2
NOD600050125
Security researchers discovered a critical TOCTOU vulnerability in Node.js’s CI/CD infrastructure that allowed attackers to execute malicious code on internal Jenkins agents. An adversary could submit a legitimate pull request, obtain approval and the request-ci label, then push new commits with forged timestamps to bypass code review checks. Once inside the pipeline, the malicious payload could establish persistence in the Jenkins environment, harvest internal credentials and move laterally across build and test systems. A parallel flaw in the commit-queue process might have enabled injection of unreviewed code directly into the main branch, threatening the entire Node.js supply chain. The Node.js security team swiftly restricted access to vulnerable Jenkins runs, rebuilt 24 compromised machines, disabled affected GitHub workflows and replaced timestamp validation with SHA-based checks. They also audited 140 Jenkins jobs to remediate gaps. Although no customer data breach was reported, the incident exposed critical internal infrastructure, credentials and trust in the build process, forcing rapid incident response and infrastructure overhaul.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Node.js ??
What was Node.js's A.I Rankiteo Cyber Score in August 2026 ??
What was Node.js's A.I Rankiteo Cyber Score in July 2026 ??
What was Node.js's A.I Rankiteo Cyber Score in June 2026 ??
What was Node.js's A.I Rankiteo Cyber Score in May 2026 ??
What was Node.js's A.I Rankiteo Cyber Score in April 2026 ??
What was Node.js's A.I Rankiteo Cyber Score in March 2026 ??
What was Node.js's A.I Rankiteo Cyber Score in February 2026 ??
What was Node.js's A.I Rankiteo Cyber Score in January 2026 ??
What was Node.js's A.I Rankiteo Cyber Score in December 2025 ??
What was Node.js's A.I Rankiteo Cyber Score in November 2025 ??
What was Node.js's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Node.js's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Node.js ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Node.js's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?