Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.
Start learningUpgrade @nestjs/microservices to version 11.2.5, 12.0.3 or higher.
@nestjs/microservices is a Nest - modern, fast, powerful node.js web framework (@microservices)
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via unbounded memory growth in the TCP transport layer of JsonSocket. On the receiving side, a peer can declare a packet length, send a partial payload, and then go silent, causing the partial packet to remain buffered indefinitely for as long as the socket stays open, with no cap on the number of such connections. On the sending side, the return value of socket.write is discarded, so a peer that issues requests without reading responses causes the process to queue every response in memory without limit. An attacker controlling a TCP peer can exploit both paths to exhaust the process heap.
Users that are not able to upgrade to the fixed version are advised to:
Restrict who can reach the port.
Lower maxBufferSize.
Supply a custom socketClass.