Dev.to Security ๐Ÿ” Cybersecurity ๐Ÿ‘ 0 ๐Ÿ“– 1 min read

CVE-2026-102281: CVE-2026-102281: Denial of Service via Uncaught Exception in @nestjs/microservices

CVE-2026-102281: Denial of Service via Uncaught Exception in @nestjs/microservices Vulnerability ID: CVE-2026-102281 CVSS Score: 7.5 Published: 2026-09-29 An unauthenticated remote attacker can crash NestJS microser

CVE-2026-102281: Denial of Service via Uncaught Exception in @nestjs/microservices

Vulnerability ID: CVE-2026-102281
CVSS Score: 7.5
Published: 2026-09-29

An unauthenticated remote attacker can crash NestJS microservices utilizing TCP or RabbitMQ transport layers. The vulnerability exists due to recursive serialization of deeply nested message patterns using JSON.stringify, leading to a RangeError and process termination.

TL;DR

A single, deeply nested pattern object can crash a NestJS microservice utilizing TCP or RabbitMQ transport due to uncaught RangeError exceptions.

Technical Details

  • CWE ID: CWE-674, CWE-248
  • Attack Vector: Network (AV:N)
  • CVSS Score: 7.5 (High)
  • EPSS Score: 0.00376 (29.01% percentile)
  • Impact: Availability (Denial of Service)
  • Exploit Status: Proof of Concept available
  • KEV Status: Not listed

Affected Systems

  • NestJS microservices using TCP or RabbitMQ transport layers
  • NestJS Microservices: < 11.2.4 (Fixed in: 11.2.4)
  • NestJS Microservices: >= 12.0.0, < 12.0.2 (Fixed in: 12.0.2)

Code Analysis

Commit: aa97b51

fix(microservices): safe serialization of incoming pattern to prevent crash

Commit: e9dcd4c

fix(microservices): backport safe serialization of pattern to v11

Exploit Details

Mitigation Strategies

  • Update dependency to secure version
  • Configure network firewall rules
  • Restrict queue publishing permissions
  • Apply runtime flags

Remediation Steps:

  1. Identify the current version of @nestjs/microservices
  2. Run 'npm install @nestjs/[email protected]' or '@nestjs/[email protected]' depending on your major version
  3. Rebuild and deploy the microservice
  4. Verify that the dependency lockfile registers the patched version

References

Read the full report for CVE-2026-102281 on our website for more details including interactive diagrams and full exploit analysis.

๐Ÿ“ฐ Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes โ€” full credit and traffic to the original publisher.