PT-2026-102385 · Nest · Nest

·

CVE-2026-102281

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Nest versions prior to 11.2.4 Nest versions prior to 12.0.2
Description A microservice using TCP or RabbitMQ transport can be terminated by a single message containing a deeply nested object in its pattern. The functions ServerTCP#handleMessage() and ServerRMQ#handleMessage() pass a client-controlled non-string pattern to JSON.stringify() to derive the handler lookup key. Sufficiently deep nesting triggers a RangeError: Maximum call stack size exceeded, leading to an unhandled promise rejection that crashes the Node.js process. This allows an attacker with access to the TCP port or the ability to publish to the consumed RabbitMQ queue or exchange to cause a denial of service.
Recommendations Update to version 11.2.4 or later. Update to version 12.0.2 or later.

Exploit

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102281
GHSA-M8VH-JMQ9-5RJG

Affected Products

Nest