PT-2026-102385 · Nest · Nest
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Nest versions prior to 11.2.4
Nest versions prior to 12.0.2
Description
A microservice using TCP or RabbitMQ transport can be terminated by a single message containing a deeply nested object in its pattern. The functions
ServerTCP#handleMessage() and ServerRMQ#handleMessage() pass a client-controlled non-string pattern to JSON.stringify() to derive the handler lookup key. Sufficiently deep nesting triggers a RangeError: Maximum call stack size exceeded, leading to an unhandled promise rejection that crashes the Node.js process. This allows an attacker with access to the TCP port or the ability to publish to the consumed RabbitMQ queue or exchange to cause a denial of service.Recommendations
Update to version 11.2.4 or later.
Update to version 12.0.2 or later.
Exploit
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nest