Executive brief
NestJS Core is a widely-used Node.js framework for building server applications. When a client cancels a request during file streaming via the StreamableFile component, the underlying file stream is not properly closed, causing resource leaks. While the impact is limited to resource exhaustion rather than data exposure, sufficient leaked connections could degrade service availability.
Technical details
This vulnerability exists in the StreamableFile pipe component of @nestjs/core versions prior to 9.0.5. The root cause is improper stream cleanup when a client cancels or abruptly terminates an HTTP request during file streaming. The vulnerability is triggered by a network-based attack vector requiring no authentication or user interaction—an attacker can simply initiate file download requests and cancel them repeatedly. When exploited, streams are left open indefinitely, consuming server resources (file descriptors, memory) until the process is restarted or the OS enforces limits. The fix, released in version 9.0.5, replaced the vulnerable `stream.pipe()` mechanism with the more robust `pipeline()` API, which automatically destroys streams on error or client disconnection. The issue affects the Express adapter specifically; Fastify handles streams correctly by default.
Affected products
- NestJS @nestjs/core < 9.0.5
Timeline
- 2023-03-06: disclosed: Vulnerability published in GitHub Advisory Database and NVD
- 2023-03-06: patched: Fix released in @nestjs/core version 9.0.5