Deepmerge ts: DeepmergeTS has stack exhaustion when merging recursive object graphs (CVE-2026-40345)
deepmerge-ts versions prior to 8.0.0 have a vulnerability where recursive merging of objects with self-references can cause stack exhaustion, leading to a crash of the Node.js process. This occurs because the merge functions do not track visited objects, causing infinite recursion. The issue is fixed in version 8.0.0.
AI Analysis
Technical Summary
The deepmerge-ts library, used for deep merging JavaScript objects, has a vulnerability (CVE-2026-40345) in versions before 8.0.0. The deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs do not track visited objects or object pairs during recursive merges. When merging objects with self-references at the same property path, the merge logic repeatedly revisits the same pairs, causing a stack overflow (RangeError: Maximum call stack size exceeded) in Node.js. This can crash the affected process or cause repeated worker restarts. Plain JSON input cannot trigger this issue as it cannot create the required recursive graph. The vulnerability is addressed in deepmerge-ts version 8.0.0.
Potential Impact
Applications using deepmerge-ts versions prior to 8.0.0 that merge attacker-controlled recursive object graphs can experience synchronous crashes due to stack exhaustion. This can lead to denial of service by crashing the Node.js process or causing repeated worker restarts. There is no indication of remote code execution or data corruption from this vulnerability.
Mitigation Recommendations
Upgrade to deepmerge-ts version 8.0.0 or later, where this issue is fixed by tracking visited objects during recursive merges. No other mitigation is required as the fix is available and official.
Deepmerge ts: DeepmergeTS has stack exhaustion when merging recursive object graphs (CVE-2026-40345)
Description
deepmerge-ts versions prior to 8.0.0 have a vulnerability where recursive merging of objects with self-references can cause stack exhaustion, leading to a crash of the Node.js process. This occurs because the merge functions do not track visited objects, causing infinite recursion. The issue is fixed in version 8.0.0.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The deepmerge-ts library, used for deep merging JavaScript objects, has a vulnerability (CVE-2026-40345) in versions before 8.0.0. The deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs do not track visited objects or object pairs during recursive merges. When merging objects with self-references at the same property path, the merge logic repeatedly revisits the same pairs, causing a stack overflow (RangeError: Maximum call stack size exceeded) in Node.js. This can crash the affected process or cause repeated worker restarts. Plain JSON input cannot trigger this issue as it cannot create the required recursive graph. The vulnerability is addressed in deepmerge-ts version 8.0.0.
Potential Impact
Applications using deepmerge-ts versions prior to 8.0.0 that merge attacker-controlled recursive object graphs can experience synchronous crashes due to stack exhaustion. This can lead to denial of service by crashing the Node.js process or causing repeated worker restarts. There is no indication of remote code execution or data corruption from this vulnerability.
Mitigation Recommendations
Upgrade to deepmerge-ts version 8.0.0 or later, where this issue is fixed by tracking visited objects during recursive merges. No other mitigation is required as the fix is available and official.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-ggr8-5vv4-36mx
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-40345"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a833354bf8831d5392a4dfd
Added to database: 08/17/2026, 16:14:12 UTC
Last enriched: 09/12/2026, 01:01:57 UTC
Last updated: 10/02/2026, 10:27:35 UTC
Views: 110
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.