Denial of Service Vulnerability in NestJS Framework Affecting Node.js Applications
CVE-2026-102281

7.5HIGH

Key Information:

Vendor

Nestjs

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-102281?

A vulnerability in the NestJS framework allows an attacker to cause a Denial of Service (DoS) by sending a deeply nested object message to a NestJS microservice utilizing TCP or RabbitMQ transports. This can result in a 'Maximum call stack size exceeded' error due to the handling of client-controlled patterns, leading to unexpected termination of the Node.js service under default behaviors. This vulnerability is mitigated in NestJS versions 11.2.4 and 12.0.2, emphasizing the importance of updating to these versions.

Affected Version(s)

nest < 11.2.4 < 11.2.4

nest >= 12.0.0, < 12.0.2 < 12.0.0, 12.0.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.