Vendor
high
threat
Path-Scoped Middleware Bypass in @nestjs/platform-fastify
2 TTPsAn improper handling of absolute-form HTTP request targets in @nestjs/platform-fastify allows attackers to bypass path-scoped middleware by inducing a path resolution mismatch between the router and the middleware layer.
exploited
@nestjs/platform-fastify +1
middleware-bypass
web-application-security
nestjs
fastify
npm
2t
low
advisory
Remote Denial of Service in NestJS Microservices via Deeply Nested Patterns
1 TTP 1 CVEAn unhandled stack overflow exception in @nestjs/microservices, triggered by deeply nested JSON message patterns, allows unauthenticated remote attackers to crash Node.js processes using TCP or RabbitMQ transports.
@nestjs/microservices +1
denial-of-service
npm
nestjs
1t
1c