@nestjs/microservices@12.0.2

Nest - modern, fast, powerful node.js web framework (@microservices)

  • latest version

    12.1.2

  • latest non vulnerable version

  • first published

    9 years ago

  • latest version published

    4 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @nestjs/microservices package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Allocation of Resources Without Limits or Throttling

    @nestjs/microservices is a Nest - modern, fast, powerful node.js web framework (@microservices)

    Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via unbounded memory growth in the TCP transport layer of JsonSocket. On the receiving side, a peer can declare a packet length, send a partial payload, and then go silent, causing the partial packet to remain buffered indefinitely for as long as the socket stays open, with no cap on the number of such connections. On the sending side, the return value of socket.write is discarded, so a peer that issues requests without reading responses causes the process to queue every response in memory without limit. An attacker controlling a TCP peer can exploit both paths to exhaust the process heap.

    How to fix Allocation of Resources Without Limits or Throttling?

    Upgrade @nestjs/microservices to version 11.2.5, 12.0.3 or higher.

    <11.2.5>=12.0.0 <12.0.3