CVE-2025-59465: Node.js
High severity, CVSS 7.5. EPSS: 4% chance of exploitation in the next 30 days.
A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that do not attach explicit error handlers to secure sockets, for example: ``` server.on('secureConnection', socket => { socket.on('error', err => { console.log(err) }) }) ```
Affected products
- Node.js Node.js: from 20.0.0, before 20.20.0 (fixed in 20.20.0); from 22.0.0, before 22.22.0 (fixed in 22.22.0); from 24.0.0, before 24.13.0 (fixed in 24.13.0); from 25.0.0, before 25.3.0 (fixed in 25.3.0)
Published 2026-01-20. Last modified 2026-07-15.