Product
The deepmerge-ts library contains a stack exhaustion vulnerability, CVE-2026-40345, that allows attackers to trigger a process crash by providing crafted, self-referencing recursive object graphs to merge functions.