Allocation of Resources Without Limits or Throttling Affecting @nestjs/microservices package, versions <11.2.5>=12.0.0 <12.0.3


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-NESTJSMICROSERVICES-20419401
  • published4 Oct 2026
  • disclosed30 Sept 2026
  • creditSalman Aljardan

Introduced: 30 Sep 2026

New CVE NOT AVAILABLE CWE-770  (opens in a new tab)

How to fix?

Upgrade @nestjs/microservices to version 11.2.5, 12.0.3 or higher.

Overview

@nestjs/microservices is a Nest - modern, fast, powerful node.js web framework (@microservices)

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via unbounded memory growth in the TCP transport layer of JsonSocket. On the receiving side, a peer can declare a packet length, send a partial payload, and then go silent, causing the partial packet to remain buffered indefinitely for as long as the socket stays open, with no cap on the number of such connections. On the sending side, the return value of socket.write is discarded, so a peer that issues requests without reading responses causes the process to queue every response in memory without limit. An attacker controlling a TCP peer can exploit both paths to exhaust the process heap.

Workaround:

Users that are not able to upgrade to the fixed version are advised to:

  1. Restrict who can reach the port.

  2. Lower maxBufferSize.

  3. Supply a custom socketClass.

CVSS Base Scores

version 4.0
version 3.1