Vulnerability GHSA-hpwf-8g29-85qm

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
5 months ago
April 14, 2026 at 12:15 AM UTC
Nest Affected by DoS via Recursive handleData in JsonSocket (TCP Transport)
2.0.0 - 11.1.18
2.0.0 - 11.1.18

Summary

Nest Affected by DoS via Recursive handleData in JsonSocket (TCP Transport)

Details

Impact

Attacker sends many small, valid JSON messages in one TCP frame → handleData() recurses once per message; buffer shrinks each call → maxBufferSize is never reached; call stack overflows instead → A ~47 KB payload is sufficient to trigger RangeError

Patches

Fixed in @nestjs/[email protected]

References

Discovered by https://github.com/hwpark6804-gif

Impacted packages

Timeline

Published
5 months ago
April 14, 2026 at 12:15 AM UTC
Fixed (11.1.19)
5 months ago
April 14, 2026 at 07:49 PM UTC
Last Modified
4 months ago
May 05, 2026 at 04:07 PM UTC