{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/nestjs/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@nestjs/platform-fastify (\u003c 11.2.4)","@nestjs/platform-fastify (12.0.0 - 12.0.1)"],"_cs_severities":["high"],"_cs_tags":["middleware-bypass","web-application-security","nestjs","fastify","npm"],"_cs_type":"threat","_cs_vendors":["NestJS"],"content_html":"\u003cp\u003eA security vulnerability in the \u003ccode\u003e@nestjs/platform-fastify\u003c/code\u003e package (versions \u0026lt; 11.2.4 and 12.0.0 to 12.0.1) allows for the bypass of path-scoped middleware. The issue originates from inconsistent path normalization between the Fastify router and the middleware engine (a bundled fork of \u003ccode\u003e@fastify/middie\u003c/code\u003e). When an attacker crafts an HTTP request using an absolute-form request target (e.g., \u003ccode\u003eGET http://host/path HTTP/1.1\u003c/code\u003e) rather than the standard origin-form (\u003ccode\u003eGET /path HTTP/1.1\u003c/code\u003e), the middleware layer fails to recognize the path correctly. Consequently, requests reach their destination route handlers without triggering path-bound security controls such as authentication, authorization, or rate-limiting. This vulnerability is particularly critical for applications that rely solely on NestJS middleware to enforce access controls on sensitive API endpoints. The issue was addressed by ensuring consistent path resolution and updating the underlying middleware engine dependency to version 9.3.4.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify protected endpoints secured by NestJS middleware.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a raw HTTP request using an absolute-form target containing the target path.\u003c/li\u003e\n\u003cli\u003eAttacker bypasses reverse proxies if the proxy configuration does not rewrite absolute-form request targets.\u003c/li\u003e\n\u003cli\u003eThe Fastify router resolves the absolute-form request to the legitimate route handler, bypassing the middleware mismatch.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003e@nestjs/platform-fastify\u003c/code\u003e middleware engine receives the absolute-form target and fails to match the configured route path due to lack of normalization.\u003c/li\u003e\n\u003cli\u003eThe application executes the controller logic for the requested endpoint without triggering the authentication or authorization middleware.\u003c/li\u003e\n\u003cli\u003eAttacker successfully retrieves protected data or performs unauthorized actions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in authentication or authorization bypass for specific API endpoints secured by NestJS middleware. This can lead to unauthorized data access, administrative command execution, or the circumvention of rate-limiting and logging controls. The impact is dependent on the sensitivity of the handlers protected by the bypassed middleware. Applications that rely on external perimeter security or reverse proxies that enforce origin-form rewriting are partially protected from this vector.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@nestjs/platform-fastify\u003c/code\u003e to version 11.2.4 or 12.0.2 (recommended 11.2.5 or 12.0.3) to resolve the underlying path resolution mismatch.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, implement a validation hook on the Fastify instance to reject non-origin-form request targets before the application processes the request.\u003c/li\u003e\n\u003cli\u003eConfigure edge reverse proxies (such as Nginx or HAProxy) to rewrite incoming absolute-form request targets to origin-form to normalize traffic before it reaches the application.\u003c/li\u003e\n\u003cli\u003eUtilize the provided proof-of-concept script using Node.js net sockets to verify that current deployments reject non-standard request line formats.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-30T16:30:22Z","date_published":"2026-09-30T16:30:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nestjs-middleware-bypass/","summary":"An improper handling of absolute-form HTTP request targets in @nestjs/platform-fastify allows attackers to bypass path-scoped middleware by inducing a path resolution mismatch between the router and the middleware layer.","title":"Path-Scoped Middleware Bypass in @nestjs/platform-fastify","url":"https://feed.craftedsignal.io/briefs/2026-09-nestjs-middleware-bypass/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nestjs:microservices:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-102281"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@nestjs/microservices (\u003e= 12.0.0 \u003c 12.0.2)","@nestjs/microservices (\u003c 11.2.4)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","npm","nestjs"],"_cs_type":"advisory","_cs_vendors":["NestJS"],"content_html":"\u003cp\u003eNestJS microservices using the \u003ccode\u003e@nestjs/microservices\u003c/code\u003e package are vulnerable to a remote denial-of-service (DoS) attack (CVE-2026-102281). The vulnerability exists within the TCP and RabbitMQ transport handlers, where the library attempts to serialize a client-supplied 'pattern' using \u003ccode\u003eJSON.stringify\u003c/code\u003e to generate a handler lookup key. An attacker can supply a specially crafted, deeply nested JSON object that is syntactically valid but causes \u003ccode\u003eJSON.stringify\u003c/code\u003e to exceed the call stack limit. This results in a \u003ccode\u003eRangeError: Maximum call stack size exceeded\u003c/code\u003e. Because the transport handlers do not implement adequate rejection handling for these asynchronous operations, the error propagates as an unhandled promise rejection, causing the Node.js process to terminate immediately. This exploit is repeatable and requires only network access to the transport layer, which is often unauthenticated by default for the TCP transport.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an exposed NestJS microservice utilizing the TCP transport on its default port (e.g., 3001) or a RabbitMQ consumer endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload containing a deeply nested JSON object within the 'pattern' field, exceeding standard recursion depths.\u003c/li\u003e\n\u003cli\u003eAttacker sends the payload to the target microservice via the transport layer (e.g., raw TCP frame or RabbitMQ message).\u003c/li\u003e\n\u003cli\u003eThe microservice receives the payload and passes the 'pattern' object to the \u003ccode\u003eJSON.stringify\u003c/code\u003e function inside the transport message handler.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eJSON.stringify\u003c/code\u003e attempts to serialize the deeply nested structure, triggering a \u003ccode\u003eRangeError: Maximum call stack size exceeded\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe error manifests as an unhandled promise rejection within the transport handler.\u003c/li\u003e\n\u003cli\u003eThe Node.js process environment (default \u003ccode\u003e--unhandled-rejections=throw\u003c/code\u003e) terminates the process, resulting in a successful denial-of-service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe attack results in a repeatable denial-of-service, rendering the microservice unresponsive by crashing the host process. The impact is significant for applications relying on microservices for core business logic, as a single crafted message can halt service availability. The vulnerability affects all NestJS services using the TCP or RabbitMQ transports that have not been patched to versions 11.2.4 or 12.0.2 respectively.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@nestjs/microservices\u003c/code\u003e to version 11.2.4 or 12.0.2 immediately to implement the required input guards and improved error handling.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2026-102281 by deploying the updated dependencies across all internet-facing or internal microservices.\u003c/li\u003e\n\u003cli\u003eRestrict network access to transport ports (TCP 3001 or RabbitMQ management/consumption ports) to authorized internal IP addresses only.\u003c/li\u003e\n\u003cli\u003eImplement infrastructure-level rate limiting and payload validation to block abnormally deeply nested JSON objects before they reach the application tier.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T04:18:57Z","date_published":"2026-09-30T04:18:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nest-microservices-dos/","summary":"An unhandled stack overflow exception in @nestjs/microservices, triggered by deeply nested JSON message patterns, allows unauthenticated remote attackers to crash Node.js processes using TCP or RabbitMQ transports.","title":"Remote Denial of Service in NestJS Microservices via Deeply Nested Patterns","url":"https://feed.craftedsignal.io/briefs/2026-09-nest-microservices-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - NestJS","version":"https://jsonfeed.org/version/1.1"}