CVE-2026-102281: CWE-248: Uncaught Exception in nestjs nest
A vulnerability in the NestJS framework prior to versions 11.2.4 and 12.0.2 allows an attacker to crash a microservice using TCP or RabbitMQ transport by sending a deeply nested object pattern. This triggers a RangeError due to exceeding the maximum call stack size during JSON.stringify, causing unhandled promise rejection and termination of the Node.js process. The issue does not affect other transports that receive patterns as strings. Fixed in versions 11.2.4 and 12.0.2.
AI Analysis
Technical Summary
NestJS versions before 11.2.4 and between 12.0.0 and 12.0.2 are vulnerable to a denial-of-service condition when handling messages with deeply nested objects in their pattern. The ServerTCP#handleMessage and ServerRMQ#handleMessage methods use JSON.stringify on a client-controlled non-string pattern to derive a handler lookup key. Deep nesting causes a RangeError: Maximum call stack size exceeded, which is not caught, leading to an unhandled promise rejection that terminates the Node.js process. This vulnerability affects microservices using TCP or RabbitMQ transports but not other transports where patterns arrive as strings. The vulnerability is resolved in versions 11.2.4 and 12.0.2.
Potential Impact
An attacker with network access to the TCP port or the ability to publish messages to the RabbitMQ queue or exchange can cause a denial-of-service by crashing the NestJS microservice. This results in service unavailability due to the Node.js process termination. There is no impact on confidentiality or integrity, only availability is affected.
Mitigation Recommendations
Upgrade affected NestJS versions to 11.2.4 or later, or 12.0.2 or later, where this issue is fixed. No other mitigations are indicated. Patch status is confirmed by the vendor advisory.
CVE-2026-102281: CWE-248: Uncaught Exception in nestjs nest
Description
A vulnerability in the NestJS framework prior to versions 11.2.4 and 12.0.2 allows an attacker to crash a microservice using TCP or RabbitMQ transport by sending a deeply nested object pattern. This triggers a RangeError due to exceeding the maximum call stack size during JSON.stringify, causing unhandled promise rejection and termination of the Node.js process. The issue does not affect other transports that receive patterns as strings. Fixed in versions 11.2.4 and 12.0.2.
CVSS v3.1
Score 7.5high
Affected software
nestjs
nest
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
NestJS versions before 11.2.4 and between 12.0.0 and 12.0.2 are vulnerable to a denial-of-service condition when handling messages with deeply nested objects in their pattern. The ServerTCP#handleMessage and ServerRMQ#handleMessage methods use JSON.stringify on a client-controlled non-string pattern to derive a handler lookup key. Deep nesting causes a RangeError: Maximum call stack size exceeded, which is not caught, leading to an unhandled promise rejection that terminates the Node.js process. This vulnerability affects microservices using TCP or RabbitMQ transports but not other transports where patterns arrive as strings. The vulnerability is resolved in versions 11.2.4 and 12.0.2.
Potential Impact
An attacker with network access to the TCP port or the ability to publish messages to the RabbitMQ queue or exchange can cause a denial-of-service by crashing the NestJS microservice. This results in service unavailability due to the Node.js process termination. There is no impact on confidentiality or integrity, only availability is affected.
Mitigation Recommendations
Upgrade affected NestJS versions to 11.2.4 or later, or 12.0.2 or later, where this issue is fixed. No other mitigations are indicated. Patch status is confirmed by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-28T20:11:16.659Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abadd1af7a7c541063c872c
Added to database: 09/28/2026, 21:33:14 UTC
Last enriched: 09/28/2026, 21:47:40 UTC
Last updated: 09/28/2026, 21:56:51 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.