Skip to main content
Vulnerability Database/CVE-2026-102281

CVE-2026-102281: NestJS Microservice DOS Vulnerability

CVE-2026-102281 is a denial of service vulnerability in NestJS microservices using TCP or RabbitMQ transport that allows attackers to crash services with deeply nested objects. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-102281 Overview

CVE-2026-102281 is a denial-of-service vulnerability in the NestJS framework, a Node.js server-side application platform. The flaw affects microservices using the TCP or RabbitMQ (RMQ) transports. A single message containing a deeply nested object in its pattern field can crash the receiving service. The ServerTCP#handleMessage and ServerRMQ#handleMessage methods pass a client-controlled non-string pattern to JSON.stringify to derive the handler lookup key. Sufficiently deep nesting triggers RangeError: Maximum call stack size exceeded, and the resulting unhandled promise rejection terminates the Node.js process under default behavior.

Critical Impact

An unauthenticated remote attacker who can reach a NestJS TCP port or publish to a consumed RabbitMQ queue can crash the microservice on demand.

Affected Products

  • NestJS framework versions prior to 11.2.4
  • NestJS framework versions prior to 12.0.2
  • Microservices using the TCP or RabbitMQ (RMQ) transport

Discovery Timeline

  • 2026-09-28 - CVE-2026-102281 published to the National Vulnerability Database
  • 2026-09-30 - CVE-2026-102281 last updated in NVD

Technical Details for CVE-2026-102281

Vulnerability Analysis

The vulnerability is an uncaught exception flaw classified under [CWE-248]. NestJS microservices dispatch inbound messages to handlers by serializing the incoming pattern field into a lookup key. When the transport delivers a structured payload rather than a raw string, the server calls JSON.stringify on the client-controlled object. JSON.stringify walks the object recursively. A pattern nested beyond the JavaScript engine's stack limit throws RangeError: Maximum call stack size exceeded.

The exception surfaces inside an async handler path. The resulting unhandled promise rejection terminates the Node.js process under the default --unhandled-rejections=throw behavior. Only TCP and RMQ transports are affected because other transports deliver patterns as strings and never invoke recursive serialization.

Root Cause

The root cause lies in trusting non-string, client-controlled input as a serialization source without depth validation or exception handling. Both ServerTCP#handleMessage and ServerRMQ#handleMessage invoked JSON.stringify on untrusted objects. The call was not wrapped in a try/catch block, and no depth or size limits were enforced prior to serialization.

Attack Vector

Any actor who can establish a TCP connection to the NestJS microservice port, or publish messages to the consumed RabbitMQ queue or exchange, can trigger the crash. No authentication or user interaction is required. A single crafted message with a pattern object nested a few thousand levels deep is sufficient to terminate the worker process.

typescript
// Patch: packages/microservices/constants.ts
// Introduces a sentinel key used when a pattern cannot be safely serialized
export const UNBLOCKED_RMQ_MESSAGE = 'RMQ broker has unblocked the connection.';

export const NATS_DEFAULT_GRACE_PERIOD = 10000;
export const UNSERIALIZABLE_PATTERN = '[UNSERIALIZABLE_PATTERN]';

Source: GitHub Commit aa97b51

The fix introduces an UNSERIALIZABLE_PATTERN sentinel and guards the JSON.stringify call so that malformed or overly nested patterns resolve to a safe key instead of throwing. See GitHub Pull Request #17737 for the full change set.

Detection Methods for CVE-2026-102281

Indicators of Compromise

  • Repeated Node.js process termination events with stack traces containing RangeError: Maximum call stack size exceeded originating in ServerTCP#handleMessage or ServerRMQ#handleMessage.
  • UnhandledPromiseRejection log entries immediately preceding worker restarts on microservice hosts.
  • Anomalous inbound TCP payloads or RabbitMQ messages containing unusually large or deeply nested JSON pattern fields.

Detection Strategies

  • Instrument NestJS microservices with process.on('unhandledRejection', ...) telemetry and forward events to centralized logging for correlation.
  • Inspect message broker traffic for pattern objects exceeding a reasonable nesting depth threshold (for example, more than 100 levels).
  • Alert on process supervisor restart loops (systemd, PM2, Kubernetes CrashLoopBackOff) tied to microservice pods hosting TCP or RMQ listeners.

Monitoring Recommendations

  • Track NestJS package versions across the software bill of materials to identify hosts still running versions below 11.2.4 or 12.0.2.
  • Monitor RabbitMQ queue publishers and TCP client source addresses for previously unseen or unauthenticated sources.
  • Correlate microservice restarts with upstream ingress logs to identify the triggering payload and source IP.

How to Mitigate CVE-2026-102281

Immediate Actions Required

  • Upgrade NestJS microservices to version 11.2.4 or 12.0.2 or later immediately.
  • Restrict network exposure of NestJS TCP transport ports to trusted internal networks only.
  • Require authentication and access controls on RabbitMQ queues and exchanges consumed by NestJS services.

Patch Information

The issue is fixed in NestJS 11.2.4 and 12.0.2. The remediation guards JSON.stringify on inbound patterns and substitutes an UNSERIALIZABLE_PATTERN sentinel when serialization fails. Review the GitHub Security Advisory GHSA-m8vh-jmq9-5rjg, Release v11.2.4, and Release v12.0.2 for release notes and commit references.

Workarounds

  • Place an application-layer proxy or message validator in front of the microservice that rejects patterns exceeding a fixed depth or size.
  • Run Node.js with --unhandled-rejections=warn as a temporary safeguard, accepting that the underlying dispatch failure is not resolved.
  • Register a global unhandledRejection handler that logs and suppresses termination until the patched version is deployed.
bash
# Upgrade NestJS microservices packages to a patched release
npm install @nestjs/microservices@^11.2.4
# or, for the 12.x line
npm install @nestjs/microservices@^12.0.2

# Verify installed version
npm ls @nestjs/microservices

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.