Junglewise Threat Intelligence

CVE-2026-40879: Nest Affected by DoS via Recursive handleData in JsonSocket (TCP Transport)

CVE-2026-40879 · Severity: high · CVSS 7.5 · Published 2026-04-14

Vendors: npm, NestJS.

Executive brief

NestJS Microservices is a library used to build scalable, distributed applications with message-based communication. An attacker can send specially crafted TCP messages containing many small JSON objects in a single frame, causing the JSON parser to recursively process each message and exhaust the application's call stack, resulting in a denial of service crash.

Technical details

The vulnerability is a stack overflow (CWE-674, CWE-770) in the JsonSocket TCP transport handler. The handleData() method recurses once per JSON message in the buffer, and each recursion shrinks the buffer without ever reaching the configured maxBufferSize limit. An attacker can send approximately 47 KB of valid JSON messages in a single TCP frame to trigger a RangeError and crash the application. The attack requires network access to the microservice but no authentication or user interaction. The issue is fixed in @nestjs/microservices version 11.1.19.

Affected products

  • NestJS Microservices <= 11.1.18

Timeline

  • 2026-04-14: disclosed: GitHub Security Advisory published
  • 2026-04-14: patched: Fixed in @nestjs/microservices@11.1.19

References