DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-102281: CVE-2026-102281: Denial of Service via Uncaught Exception in @nestjs/microservices

CVE-2026-102281: Denial of Service via Uncaught Exception in @nestjs/microservices

Vulnerability ID: CVE-2026-102281
CVSS Score: 7.5
Published: 2026-09-29

An unauthenticated remote attacker can crash NestJS microservices utilizing TCP or RabbitMQ transport layers. The vulnerability exists due to recursive serialization of deeply nested message patterns using JSON.stringify, leading to a RangeError and process termination.

TL;DR

A single, deeply nested pattern object can crash a NestJS microservice utilizing TCP or RabbitMQ transport due to uncaught RangeError exceptions.


Technical Details

  • CWE ID: CWE-674, CWE-248
  • Attack Vector: Network (AV:N)
  • CVSS Score: 7.5 (High)
  • EPSS Score: 0.00376 (29.01% percentile)
  • Impact: Availability (Denial of Service)
  • Exploit Status: Proof of Concept available
  • KEV Status: Not listed

Affected Systems

  • NestJS microservices using TCP or RabbitMQ transport layers
  • NestJS Microservices: < 11.2.4 (Fixed in: 11.2.4)
  • NestJS Microservices: >= 12.0.0, < 12.0.2 (Fixed in: 12.0.2)

Code Analysis

Commit: aa97b51

fix(microservices): safe serialization of incoming pattern to prevent crash

Commit: e9dcd4c

fix(microservices): backport safe serialization of pattern to v11

Exploit Details

Mitigation Strategies

  • Update dependency to secure version
  • Configure network firewall rules
  • Restrict queue publishing permissions
  • Apply runtime flags

Remediation Steps:

  1. Identify the current version of @nestjs/microservices
  2. Run 'npm install @nestjs/microservices@11.2.4' or '@nestjs/microservices@12.0.2' depending on your major version
  3. Rebuild and deploy the microservice
  4. Verify that the dependency lockfile registers the patched version

References


Read the full report for CVE-2026-102281 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)