{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anestjsmicroservices/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nestjs:microservices:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-102281"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@nestjs/microservices (\u003e= 12.0.0 \u003c 12.0.2)","@nestjs/microservices (\u003c 11.2.4)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","npm","nestjs"],"_cs_type":"advisory","_cs_vendors":["NestJS"],"content_html":"\u003cp\u003eNestJS microservices using the \u003ccode\u003e@nestjs/microservices\u003c/code\u003e package are vulnerable to a remote denial-of-service (DoS) attack (CVE-2026-102281). The vulnerability exists within the TCP and RabbitMQ transport handlers, where the library attempts to serialize a client-supplied 'pattern' using \u003ccode\u003eJSON.stringify\u003c/code\u003e to generate a handler lookup key. An attacker can supply a specially crafted, deeply nested JSON object that is syntactically valid but causes \u003ccode\u003eJSON.stringify\u003c/code\u003e to exceed the call stack limit. This results in a \u003ccode\u003eRangeError: Maximum call stack size exceeded\u003c/code\u003e. Because the transport handlers do not implement adequate rejection handling for these asynchronous operations, the error propagates as an unhandled promise rejection, causing the Node.js process to terminate immediately. This exploit is repeatable and requires only network access to the transport layer, which is often unauthenticated by default for the TCP transport.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an exposed NestJS microservice utilizing the TCP transport on its default port (e.g., 3001) or a RabbitMQ consumer endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload containing a deeply nested JSON object within the 'pattern' field, exceeding standard recursion depths.\u003c/li\u003e\n\u003cli\u003eAttacker sends the payload to the target microservice via the transport layer (e.g., raw TCP frame or RabbitMQ message).\u003c/li\u003e\n\u003cli\u003eThe microservice receives the payload and passes the 'pattern' object to the \u003ccode\u003eJSON.stringify\u003c/code\u003e function inside the transport message handler.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eJSON.stringify\u003c/code\u003e attempts to serialize the deeply nested structure, triggering a \u003ccode\u003eRangeError: Maximum call stack size exceeded\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe error manifests as an unhandled promise rejection within the transport handler.\u003c/li\u003e\n\u003cli\u003eThe Node.js process environment (default \u003ccode\u003e--unhandled-rejections=throw\u003c/code\u003e) terminates the process, resulting in a successful denial-of-service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe attack results in a repeatable denial-of-service, rendering the microservice unresponsive by crashing the host process. The impact is significant for applications relying on microservices for core business logic, as a single crafted message can halt service availability. The vulnerability affects all NestJS services using the TCP or RabbitMQ transports that have not been patched to versions 11.2.4 or 12.0.2 respectively.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@nestjs/microservices\u003c/code\u003e to version 11.2.4 or 12.0.2 immediately to implement the required input guards and improved error handling.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2026-102281 by deploying the updated dependencies across all internet-facing or internal microservices.\u003c/li\u003e\n\u003cli\u003eRestrict network access to transport ports (TCP 3001 or RabbitMQ management/consumption ports) to authorized internal IP addresses only.\u003c/li\u003e\n\u003cli\u003eImplement infrastructure-level rate limiting and payload validation to block abnormally deeply nested JSON objects before they reach the application tier.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T04:18:57Z","date_published":"2026-09-30T04:18:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nest-microservices-dos/","summary":"An unhandled stack overflow exception in @nestjs/microservices, triggered by deeply nested JSON message patterns, allows unauthenticated remote attackers to crash Node.js processes using TCP or RabbitMQ transports.","title":"Remote Denial of Service in NestJS Microservices via Deeply Nested Patterns","url":"https://feed.craftedsignal.io/briefs/2026-09-nest-microservices-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:nestjs:microservices:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}