CVE-2026-102281 NestJS 微服务拒绝服务漏洞
影响攻击者可远程触发拒绝服务,导致微服务进程崩溃
NestJS 是一个用于构建可扩展 Node.js 服务端应用的框架。在其 11.2.4 和 12.0.2 之前的版本中,TCP 与 RabbitMQ 传输层在处理消息时,会将客户端可控的非字符串 pattern 传入 JSON.stringify 生成处理器查找键。当嵌套层级过深时会抛出 RangeError,未处理的 Promise 拒绝在 Node.js 默认行为下会终止进程。
影响范围
NestJS 11.2.4 之前版本及 12.0.2 之前版本,仅影响使用 TCP 或 RabbitMQ 传输的微服务;其他传输方式不受影响。
漏洞详情
漏洞类型为拒绝服务(栈溢出导致进程终止)。成因是 ServerTCP#handleMessage 与 ServerRMQ#handleMessage 未校验 pattern 类型,直接对客户端传入的对象执行 JSON.stringify,深度嵌套对象会触发 RangeError: Maximum call stack size exceeded。由于该异常未被捕获,形成未处理的 Promise 拒绝,在 Node.js 默认行为下进程直接退出。
利用条件与风险
利用前提是攻击者能够访问 TCP 端口,或向被消费的 RabbitMQ 队列/交换机发布消息,无需认证即可按需使服务崩溃,实战风险较高。
修复建议
官方已在 11.2.4 和 12.0.2 版本中修复,建议尽快升级;临时缓解措施包括限制 TCP 端口与 RabbitMQ 队列的网络访问、对消息 pattern 做类型与深度校验,暂无其他公开信息。
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a NestJS microservice using the TCP or RabbitMQ transport. ServerTCP#handleMessage and ServerRMQ#handleMessage pass a client-controlled non-string pattern to JSON.stringify to derive the handler lookup key; sufficiently deep nesting throws RangeError: Maximum call stack size exceeded, and the unhandled promise rejection terminates Node.js under its default behavior. An attacker who can reach the TCP port or publish to the consumed RabbitMQ queue or exchange can crash the service on demand; other transports are not affected because their patterns arrive as strings. This issue is fixed in versions 11.2.4 and 12.0.2.