Advisories for Npm/@Nestjs/Microservices package

2026

Nest: Unbounded memory growth in the NestJS TCP microservice transport

A peer that can open a TCP connection to a NestJS microservice using the built-in TCP transport can make the server process allocate memory without limit, on either side of the connection, until the process is killed by the OS or by its container memory limit. No authentication, no credentials, and no valid message are required. Applications are affected only if they start a microservice with Transport.TCP and the transport's …

Nest: Remote process termination via a deeply nested microservice message pattern

A single message whose pattern is a deeply nested object terminates a NestJS microservice that uses the TCP or RabbitMQ transport. The server serialized the client-supplied pattern with JSON.stringify to derive the handler lookup key; on deeply nested input this throws RangeError: Maximum call stack size exceeded. The exception escaped the asynchronous message handler as an unhandled promise rejection, which terminates the Node.js process under the default –unhandled-rejections=throw.