<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:nestjs:microservices:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3anestjsmicroservices/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 04:18:57 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3anestjsmicroservices/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Denial of Service in NestJS Microservices via Deeply Nested Patterns</title><link>https://feed.craftedsignal.io/briefs/2026-09-nest-microservices-dos/</link><pubDate>Wed, 30 Sep 2026 04:18:57 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-nest-microservices-dos/</guid><description>An unhandled stack overflow exception in @nestjs/microservices, triggered by deeply nested JSON message patterns, allows unauthenticated remote attackers to crash Node.js processes using TCP or RabbitMQ transports.</description><content:encoded><![CDATA[<p>NestJS microservices using the <code>@nestjs/microservices</code> package are vulnerable to a remote denial-of-service (DoS) attack (CVE-2026-102281). The vulnerability exists within the TCP and RabbitMQ transport handlers, where the library attempts to serialize a client-supplied 'pattern' using <code>JSON.stringify</code> to generate a handler lookup key. An attacker can supply a specially crafted, deeply nested JSON object that is syntactically valid but causes <code>JSON.stringify</code> to exceed the call stack limit. This results in a <code>RangeError: Maximum call stack size exceeded</code>. Because the transport handlers do not implement adequate rejection handling for these asynchronous operations, the error propagates as an unhandled promise rejection, causing the Node.js process to terminate immediately. This exploit is repeatable and requires only network access to the transport layer, which is often unauthenticated by default for the TCP transport.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies an exposed NestJS microservice utilizing the TCP transport on its default port (e.g., 3001) or a RabbitMQ consumer endpoint.</li>
<li>Attacker crafts a malicious payload containing a deeply nested JSON object within the 'pattern' field, exceeding standard recursion depths.</li>
<li>Attacker sends the payload to the target microservice via the transport layer (e.g., raw TCP frame or RabbitMQ message).</li>
<li>The microservice receives the payload and passes the 'pattern' object to the <code>JSON.stringify</code> function inside the transport message handler.</li>
<li><code>JSON.stringify</code> attempts to serialize the deeply nested structure, triggering a <code>RangeError: Maximum call stack size exceeded</code>.</li>
<li>The error manifests as an unhandled promise rejection within the transport handler.</li>
<li>The Node.js process environment (default <code>--unhandled-rejections=throw</code>) terminates the process, resulting in a successful denial-of-service.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The attack results in a repeatable denial-of-service, rendering the microservice unresponsive by crashing the host process. The impact is significant for applications relying on microservices for core business logic, as a single crafted message can halt service availability. The vulnerability affects all NestJS services using the TCP or RabbitMQ transports that have not been patched to versions 11.2.4 or 12.0.2 respectively.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for detection and remediation:</p>
<ul>
<li>Upgrade <code>@nestjs/microservices</code> to version 11.2.4 or 12.0.2 immediately to implement the required input guards and improved error handling.</li>
<li>Patch CVE-2026-102281 by deploying the updated dependencies across all internet-facing or internal microservices.</li>
<li>Restrict network access to transport ports (TCP 3001 or RabbitMQ management/consumption ports) to authorized internal IP addresses only.</li>
<li>Implement infrastructure-level rate limiting and payload validation to block abnormally deeply nested JSON objects before they reach the application tier.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>npm</category><category>nestjs</category></item></channel></rss>