CVE-2026-102281
Received Received - Intake

Stack Overflow in NestJS Microservices with TCP/RabbitMQ

Vulnerability report for CVE-2026-102281, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a NestJS microservice using the TCP or RabbitMQ transport. ServerTCP#handleMessage and ServerRMQ#handleMessage pass a client-controlled non-string pattern to JSON.stringify to derive the handler lookup key; sufficiently deep nesting throws RangeError: Maximum call stack size exceeded, and the unhandled promise rejection terminates Node.js under its default behavior. An attacker who can reach the TCP port or publish to the consumed RabbitMQ queue or exchange can crash the service on demand; other transports are not affected because their patterns arrive as strings. This issue is fixed in versions 11.2.4 and 12.0.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nestjs nest to 12.0.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects NestJS, a Node.js framework for building server-side applications. It allows an attacker to crash a NestJS microservice by sending a single message with a deeply nested object in its pattern. The service crashes because the pattern is passed to JSON.stringify, which throws a 'Maximum call stack size exceeded' error due to excessive nesting depth.

Detection Guidance

To detect this vulnerability, monitor for crashes in NestJS microservices using TCP or RabbitMQ transport. Check for RangeError exceptions in logs when handling deeply nested objects. Use network scanning tools to identify services running vulnerable versions (pre-11.2.4 or 12.0.2).

Commands: netstat -tuln | grep <port> to check TCP ports, rabbitmqctl list_queues to inspect RabbitMQ queues, and npm list @nestjs/microservices to verify installed versions.

Impact Analysis

If you use NestJS microservices with TCP or RabbitMQ transport, an attacker could crash your service by sending a specially crafted message. This could lead to denial of service, disrupting your application's availability. Other transports are not affected.

Compliance Impact

This vulnerability could lead to denial-of-service (DoS) conditions by crashing NestJS microservices using TCP or RabbitMQ transports. For GDPR, this may impact availability of services processing personal data, potentially violating Article 32 requirements for resilience. For HIPAA, service disruptions could affect systems handling protected health information, compromising integrity and availability requirements under the Security Rule.

Mitigation Strategies

Upgrade NestJS to versions 11.2.4 or 12.0.2 or later. If immediate upgrade is not possible, restrict access to TCP ports and RabbitMQ queues using firewalls. Implement input validation to prevent deeply nested objects in messages.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102281. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart