{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/deepmerge-ts--8.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["deepmerge-ts (\u003c 8.0.0)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe deepmerge-ts library (versions prior to 8.0.0) is susceptible to a denial-of-service attack due to a flaw in its recursive object merging logic. The library recursively traverses object trees to perform merges but lacks cycle detection or tracking for visited object pairs. An attacker who can influence the input objects passed to functions such as \u003ccode\u003edeepmerge()\u003c/code\u003e, \u003ccode\u003edeepmergeInto()\u003c/code\u003e, or their custom variations can provide a crafted object graph containing self-references. When the library attempts to merge these structures, it enters an infinite recursion, eventually causing the Node.js runtime to throw a 'RangeError: Maximum call stack size exceeded'. This vulnerability impacts applications that allow users to submit complex or serialized objects for server-side processing, potentially leading to repeated service crashes and availability loss.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eApplications that process attacker-supplied object structures using vulnerable versions of deepmerge-ts are at risk of a synchronous service crash. In Node.js-based environments, this can lead to unhandled exceptions that terminate the process. In clustered or managed environments, this may trigger frequent worker restarts, effectively creating a persistent denial-of-service state for the targeted application endpoint.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the deepmerge-ts dependency to version 8.0.0 or later to include the required cycle detection logic.\u003c/li\u003e\n\u003cli\u003eAudit all application endpoints that accept user-provided JSON or object structures for processing to ensure input is validated before being passed to deepmerge-ts.\u003c/li\u003e\n\u003cli\u003eMonitor logs for repeated 'RangeError: Maximum call stack size exceeded' exceptions linked to application processes to identify potential exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-17T18:47:21Z","date_published":"2026-08-17T18:47:21Z","id":"https://feed.craftedsignal.io/briefs/2026-08-deepmerge-ts-stack-exhaustion/","summary":"The deepmerge-ts library contains a stack exhaustion vulnerability, CVE-2026-40345, that allows attackers to trigger a process crash by providing crafted, self-referencing recursive object graphs to merge functions.","title":"Stack Exhaustion Vulnerability in deepmerge-ts","url":"https://feed.craftedsignal.io/briefs/2026-08-deepmerge-ts-stack-exhaustion/"}],"language":"en","title":"CraftedSignal Threat Feed - Deepmerge-Ts (\u003c 8.0.0)","version":"https://jsonfeed.org/version/1.1"}