Denial of Service Vulnerability in NestJS Framework Affecting Node.js Applications
CVE-2026-102281
7.5HIGH
What is CVE-2026-102281?
A vulnerability in the NestJS framework allows an attacker to cause a Denial of Service (DoS) by sending a deeply nested object message to a NestJS microservice utilizing TCP or RabbitMQ transports. This can result in a 'Maximum call stack size exceeded' error due to the handling of client-controlled patterns, leading to unexpected termination of the Node.js service under default behaviors. This vulnerability is mitigated in NestJS versions 11.2.4 and 12.0.2, emphasizing the importance of updating to these versions.
Affected Version(s)
nest < 11.2.4 < 11.2.4
nest >= 12.0.0, < 12.0.2 < 12.0.0, 12.0.2
