CVE-2026-102281: CVE-2026-102281: Denial of Service via Uncaught Exception in @nestjs/microservices
CVE-2026-102281: Denial of Service via Uncaught Exception in @nestjs/microservices Vulnerability ID: CVE-2026-102281 CVSS Score: 7.5 Published: 2026-09-29 An unauthenticated remote attacker can crash NestJS microser
CVE-2026-102281: Denial of Service via Uncaught Exception in @nestjs/microservices
Vulnerability ID: CVE-2026-102281
CVSS Score: 7.5
Published: 2026-09-29
An unauthenticated remote attacker can crash NestJS microservices utilizing TCP or RabbitMQ transport layers. The vulnerability exists due to recursive serialization of deeply nested message patterns using JSON.stringify, leading to a RangeError and process termination.
TL;DR
A single, deeply nested pattern object can crash a NestJS microservice utilizing TCP or RabbitMQ transport due to uncaught RangeError exceptions.
Technical Details
- CWE ID: CWE-674, CWE-248
- Attack Vector: Network (AV:N)
- CVSS Score: 7.5 (High)
- EPSS Score: 0.00376 (29.01% percentile)
- Impact: Availability (Denial of Service)
- Exploit Status: Proof of Concept available
- KEV Status: Not listed
Affected Systems
- NestJS microservices using TCP or RabbitMQ transport layers
-
NestJS Microservices: < 11.2.4 (Fixed in:
11.2.4) -
NestJS Microservices: >= 12.0.0, < 12.0.2 (Fixed in:
12.0.2)
Code Analysis
Commit: aa97b51
fix(microservices): safe serialization of incoming pattern to prevent crash
Commit: e9dcd4c
fix(microservices): backport safe serialization of pattern to v11
Exploit Details
- Vulnerability Research Report: Reproduction test case and advisory detailing pattern recursion
Mitigation Strategies
- Update dependency to secure version
- Configure network firewall rules
- Restrict queue publishing permissions
- Apply runtime flags
Remediation Steps:
- Identify the current version of @nestjs/microservices
- Run 'npm install @nestjs/[email protected]' or '@nestjs/[email protected]' depending on your major version
- Rebuild and deploy the microservice
- Verify that the dependency lockfile registers the patched version
References
- GitHub Security Advisory
- Pull Request Fix
- Fix Commit (Main Branch)
- Fix Commit (v11 Branch)
- NVD Vulnerability Details
Read the full report for CVE-2026-102281 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes โ full credit and traffic to the original publisher.