CWE-674
Allowed-with-ReviewUncontrolled Recursion
Abstraction: Class · Status: Draft
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
850 vulnerabilities reference this CWE, most recent first.
GHSA-J7VJ-RW65-4V26
Vulnerability from github – Published: 2024-09-06 21:32 – Updated: 2024-09-09 15:30Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.
{
"affected": [],
"aliases": [
"CVE-2024-34158"
],
"database_specific": {
"cwe_ids": [
"CWE-674"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-06T21:15:12Z",
"severity": "HIGH"
},
"details": "Calling Parse on a \"// +build\" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.",
"id": "GHSA-j7vj-rw65-4v26",
"modified": "2024-09-09T15:30:38Z",
"published": "2024-09-06T21:32:28Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34158"
},
{
"type": "WEB",
"url": "https://go.dev/cl/611240"
},
{
"type": "WEB",
"url": "https://go.dev/issue/69141"
},
{
"type": "WEB",
"url": "https://groups.google.com/g/golang-dev/c/S9POB9NCTdk"
},
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2024-3107"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-J87P-GJR6-M4PV
Vulnerability from github – Published: 2025-07-27 21:32 – Updated: 2025-07-28 15:54Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-rr69-rxr6-8qwf. This link is maintained to preserve external references.
Original Description
The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data.
{
"affected": [
{
"package": {
"ecosystem": "crates.io",
"name": "serde-json-wasm"
},
"ranges": [
{
"events": [
{
"introduced": "1.0.0"
},
{
"fixed": "1.0.1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.0.0"
]
},
{
"package": {
"ecosystem": "crates.io",
"name": "serde-json-wasm"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.5.2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [],
"database_specific": {
"cwe_ids": [
"CWE-674"
],
"github_reviewed": true,
"github_reviewed_at": "2025-07-28T15:54:52Z",
"nvd_published_at": "2025-07-27T21:15:26Z",
"severity": "LOW"
},
"details": "### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-rr69-rxr6-8qwf. This link is maintained to preserve external references.\n\n### Original Description\nThe serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data.",
"id": "GHSA-j87p-gjr6-m4pv",
"modified": "2025-07-28T15:54:52Z",
"published": "2025-07-27T21:32:12Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58264"
},
{
"type": "WEB",
"url": "https://crates.io/crates/serde-json-wasm"
},
{
"type": "PACKAGE",
"url": "https://github.com/CosmWasm/serde-json-wasm"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-rr69-rxr6-8qwf"
},
{
"type": "WEB",
"url": "https://rustsec.org/advisories/RUSTSEC-2024-0012.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L",
"type": "CVSS_V3"
}
],
"summary": "Duplicate Advisory: serde-json-wasm stack overflow during recursive JSON parsing",
"withdrawn": "2025-07-28T15:54:52Z"
}
GHSA-J9VR-6635-6998
Vulnerability from github – Published: 2022-05-24 17:00 – Updated: 2022-05-24 17:00ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly restricted in coders/svg.c, related to SVG and libxml2.
{
"affected": [],
"aliases": [
"CVE-2019-18853"
],
"database_specific": {
"cwe_ids": [
"CWE-674"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-11-11T15:15:00Z",
"severity": "MODERATE"
},
"details": "ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly restricted in coders/svg.c, related to SVG and libxml2.",
"id": "GHSA-j9vr-6635-6998",
"modified": "2022-05-24T17:00:42Z",
"published": "2022-05-24T17:00:42Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-18853"
},
{
"type": "WEB",
"url": "https://github.com/ImageMagick/ImageMagick/commit/ec9c8944af2bfc65c697ca44f93a727a99b405f1"
},
{
"type": "WEB",
"url": "https://fortiguard.com/zeroday/FG-VD-19-136"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-JCQV-RJ94-JMX3
Vulnerability from github – Published: 2026-07-16 00:31 – Updated: 2026-07-20 18:32A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
{
"affected": [],
"aliases": [
"CVE-2026-38755"
],
"database_specific": {
"cwe_ids": [
"CWE-122",
"CWE-674"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-15T22:16:47Z",
"severity": "HIGH"
},
"details": "A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.",
"id": "GHSA-jcqv-rj94-jmx3",
"modified": "2026-07-20T18:32:26Z",
"published": "2026-07-16T00:31:34Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-38755"
},
{
"type": "WEB",
"url": "https://busybox.com"
},
{
"type": "WEB",
"url": "https://busybox.net"
},
{
"type": "WEB",
"url": "https://lists.busybox.net/pipermail/busybox/2026-June/092354.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-JCX2-5QW3-59P6
Vulnerability from github – Published: 2022-05-24 19:21 – Updated: 2022-05-24 19:21Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
{
"affected": [],
"aliases": [
"CVE-2021-39929"
],
"database_specific": {
"cwe_ids": [
"CWE-674"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-11-19T17:15:00Z",
"severity": "HIGH"
},
"details": "Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file",
"id": "GHSA-jcx2-5qw3-59p6",
"modified": "2022-05-24T19:21:07Z",
"published": "2022-05-24T19:21:07Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-39929"
},
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39929.json"
},
{
"type": "WEB",
"url": "https://gitlab.com/wireshark/wireshark/-/issues/17651"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2021/12/msg00015.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A6AJFIYIHS3TYDD2EBYBJ5KKE52X34BJ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YEWTIRMC2MFQBZ2O5M4CJHJM4JPBHLXH"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202210-04"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2021/dsa-5019"
},
{
"type": "WEB",
"url": "https://www.wireshark.org/security/wnpa-sec-2021-07.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-JFW3-2GCF-23R5
Vulnerability from github – Published: 2026-09-15 18:32 – Updated: 2026-09-15 18:32vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and terminate the API process.
{
"affected": [],
"aliases": [
"CVE-2026-91968"
],
"database_specific": {
"cwe_ids": [
"CWE-674"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-15T16:17:53Z",
"severity": "HIGH"
},
"details": "vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and terminate the API process.",
"id": "GHSA-jfw3-2gcf-23r5",
"modified": "2026-09-15T18:32:30Z",
"published": "2026-09-15T18:32:30Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xxc3-xpmc-vmvr"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91968"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/vikunja-before-2.6.0-denial-of-service-via-unbounded-filter-recursion"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-JG4X-P32P-Q6XR
Vulnerability from github – Published: 2026-08-16 15:30 – Updated: 2026-08-16 15:30Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an uncatchable StackOverflowException that immediately terminates the host process.
{
"affected": [],
"aliases": [
"CVE-2026-74783"
],
"database_specific": {
"cwe_ids": [
"CWE-674"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-08-16T14:16:56Z",
"severity": "HIGH"
},
"details": "Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an uncatchable StackOverflowException that immediately terminates the host process.",
"id": "GHSA-jg4x-p32p-q6xr",
"modified": "2026-08-16T15:30:26Z",
"published": "2026-08-16T15:30:26Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/scriban/scriban/security/advisories/GHSA-6q7j-xr26-3h2c"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74783"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/scriban-through-parser-recursion-denial-of-service"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-JGGG-4JG4-V7C6
Vulnerability from github – Published: 2026-05-19 16:21 – Updated: 2026-05-19 16:21Summary
protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON().
A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading.
Impact
An attacker who can provide JSON descriptors loaded by an application may be able to crash the process or otherwise cause schema loading to fail with a stack overflow.
This affects applications that load JSON descriptors from untrusted sources with affected versions.
Preconditions
- The application must load JSON descriptor data influenced by an attacker.
- The crafted descriptor must contain deeply nested
nestednamespace objects. - The affected
Root.fromJSON()/Namespace.addJSON()descriptor expansion path must process the crafted input.
Workarounds
Avoid loading untrusted protobuf JSON descriptors with affected versions. If immediate upgrade is not possible, reject excessively nested descriptor structures at an outer validation boundary where feasible, or isolate descriptor loading in a process that can be safely restarted.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 7.5.7"
},
"package": {
"ecosystem": "npm",
"name": "protobufjs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "7.5.8"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "npm",
"name": "protobufjs"
},
"ranges": [
{
"events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.2.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-45740"
],
"database_specific": {
"cwe_ids": [
"CWE-674"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-19T16:21:33Z",
"nvd_published_at": "2026-05-13T16:17:00Z",
"severity": "MODERATE"
},
"details": "## Summary\n\nprotobufjs could recurse without a depth limit while expanding nested JSON descriptors through `Root.fromJSON()` and `Namespace.addJSON()`.\n\nA crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading.\n\n## Impact\n\nAn attacker who can provide JSON descriptors loaded by an application may be able to crash the process or otherwise cause schema loading to fail with a stack overflow.\n\nThis affects applications that load JSON descriptors from untrusted sources with affected versions.\n\n## Preconditions\n\n- The application must load JSON descriptor data influenced by an attacker.\n- The crafted descriptor must contain deeply nested `nested` namespace objects.\n- The affected `Root.fromJSON()` / `Namespace.addJSON()` descriptor expansion path must process the crafted input.\n\n## Workarounds\n\nAvoid loading untrusted protobuf JSON descriptors with affected versions. If immediate upgrade is not possible, reject excessively nested descriptor structures at an outer validation boundary where feasible, or isolate descriptor loading in a process that can be safely restarted.",
"id": "GHSA-jggg-4jg4-v7c6",
"modified": "2026-05-19T16:21:34Z",
"published": "2026-05-19T16:21:33Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-jggg-4jg4-v7c6"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45740"
},
{
"type": "PACKAGE",
"url": "https://github.com/protobufjs/protobuf.js"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"type": "CVSS_V3"
}
],
"summary": "protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion"
}
GHSA-JGGJ-J5FQ-X969
Vulnerability from github – Published: 2026-05-05 03:31 – Updated: 2026-05-09 06:31An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine stack. The stack is allocated without a guard page, which means that a stack overflow could overwrite memory on the heap and could allow arbitrary code execution as the Nix daemon (run as root in multi-user installations) if ASLR hardening is bypassed. This can be exploited by all users able to connect to the daemon (e.g., in Nix, this is configurable via the allowed-users setting, defaulting to all users). The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 for Nix (introduced in 2.24.4); and 2.95.2, 2.94.2, and 2.93.4 for Lix (introduced in 2.93.0).
{
"affected": [],
"aliases": [
"CVE-2026-44028"
],
"database_specific": {
"cwe_ids": [
"CWE-674"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-05-05T01:16:06Z",
"severity": "HIGH"
},
"details": "An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine stack. The stack is allocated without a guard page, which means that a stack overflow could overwrite memory on the heap and could allow arbitrary code execution as the Nix daemon (run as root in multi-user installations) if ASLR hardening is bypassed. This can be exploited by all users able to connect to the daemon (e.g., in Nix, this is configurable via the allowed-users setting, defaulting to all users). The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 for Nix (introduced in 2.24.4); and 2.95.2, 2.94.2, and 2.93.4 for Lix (introduced in 2.93.0).",
"id": "GHSA-jggj-j5fq-x969",
"modified": "2026-05-09T06:31:35Z",
"published": "2026-05-05T03:31:41Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/NixOS/nix/security/advisories/GHSA-vh5x-56v6-4368"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44028"
},
{
"type": "WEB",
"url": "https://discourse.nixos.org/t/security-advisory-local-privilege-escalation-in-lix-and-nix/77407"
},
{
"type": "WEB",
"url": "https://lix.systems/blog/2026-05-05-lix-unsigned-integer-overflow"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2026/05/04/32"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2026/05/04/33"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-JGGR-W7FW-PC2J
Vulnerability from github – Published: 2026-10-05 22:52 – Updated: 2026-10-05 22:52Summary
fast-copy traverses values recursively with no bound on depth. Copying a sufficiently deeply-nested value exhausts the JavaScript call stack and throws a native RangeError: Maximum call stack size exceeded from inside the library.
Details
Both copy and copyStrict recurse once per level of nesting. The value does not need to be circular (circular references were already handled correctly via an internal cache) and it does not need to be large. A plain object nested a few thousand levels deep is only a few
kilobytes of equivalent JSON.
Measured depths at which copying begins to fail (Node.js, V8; the exact ceiling varies with JIT state and the stack available to the environment):
| Call | Last depth that copies successfully |
|---|---|
copy(object) |
2811 |
copy(array) |
3983 |
copyStrict(object) |
1874 |
copyStrict(array) |
1874 |
JSON.parse is iterative and parses deeply-nested input without difficulty, so a payload that deserializes cleanly can fail in a subsequent copy call.
Impact
The failure is a synchronous, catchable RangeError confined to the copy call that received the value. There are no memory safety concerns, no data exposure, and no effect on state outside that call. In a typical server the result is a failed request rather than a failed process.
Applications that call copy on externally-supplied data, such as request bodies, cached payloads, merged configuration, etc., do not expect a clone helper to throw may surface this as an unhandled error.
Patches
Fixed in 4.1.0, and backported to 3.1.0 and 2.2.0 so that every major line has a patch available without requiring a breaking upgrade.
Traversal is now bounded by a maxDepth option, defaulting to 1000, which sits below the native limit in standard environments. Exceeding it throws MaxDepthExceededError, which carries the limit that was exceeded and extends RangeError so existing handling continues to match.
The limit is configurable for consumers with legitimately deep data. On 3.x and 4.x it is set when creating a copier:
import { createCopier } from 'fast-copy';
export const copy = createCopier({ maxDepth: 5000 });
On 2.x it is passed per call, and the error is a property of the exported function rather than a named export:
import copy from 'fast-copy';
copy(value, { maxDepth: 5000 });
// detection: error instanceof copy.MaxDepthExceededError
In legacy environments without Object.setPrototypeOf, instanceof MaxDepthExceededError cannot be supported; check error.name === 'MaxDepthExceededError' or error instanceof RangeError instead.
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "fast-copy"
},
"ranges": [
{
"events": [
{
"introduced": "4.0.0"
},
{
"fixed": "4.1.0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "npm",
"name": "fast-copy"
},
"ranges": [
{
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.1.0"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "npm",
"name": "fast-copy"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.2.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [],
"database_specific": {
"cwe_ids": [
"CWE-674"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-05T22:52:09Z",
"nvd_published_at": null,
"severity": "MODERATE"
},
"details": "## Summary\n\n`fast-copy` traverses values recursively with no bound on depth. Copying a sufficiently deeply-nested value exhausts the JavaScript call stack and throws a native `RangeError: Maximum call stack size exceeded` from inside the library.\n\n## Details\n\nBoth `copy` and `copyStrict` recurse once per level of nesting. The value does not need to be circular (circular references were already handled correctly via an internal cache) and it does not need to be large. A plain object nested a few thousand levels deep is only a few\nkilobytes of equivalent JSON.\n\nMeasured depths at which copying begins to fail (Node.js, V8; the exact ceiling varies with JIT state and the stack available to the environment):\n\n| Call | Last depth that copies successfully |\n| -------------------- | ----------------------------------- |\n| `copy(object)` | 2811 |\n| `copy(array)` | 3983 |\n| `copyStrict(object)` | 1874 |\n| `copyStrict(array)` | 1874 |\n\n`JSON.parse` is iterative and parses deeply-nested input without difficulty, so a payload that deserializes cleanly can fail in a subsequent `copy` call.\n\n## Impact\n\nThe failure is a synchronous, catchable `RangeError` confined to the `copy` call that received the value. There are no memory safety concerns, no data exposure, and no effect on state outside that call. In a typical server the result is a failed request rather than a failed process.\n\nApplications that call `copy` on externally-supplied data, such as request bodies, cached payloads, merged configuration, etc., do not expect a clone helper to throw may surface this as an unhandled error.\n\n## Patches\n\nFixed in 4.1.0, and backported to 3.1.0 and 2.2.0 so that every major line has a patch available without requiring a breaking upgrade.\n\nTraversal is now bounded by a `maxDepth` option, defaulting to `1000`, which sits below the native limit in standard environments. Exceeding it throws `MaxDepthExceededError`, which carries the limit that was exceeded and extends `RangeError` so existing handling continues to match.\n\nThe limit is configurable for consumers with legitimately deep data. On `3.x` and `4.x` it is set when creating a copier:\n\n```js\nimport { createCopier } from \u0027fast-copy\u0027;\n\nexport const copy = createCopier({ maxDepth: 5000 });\n```\n\nOn `2.x` it is passed per call, and the error is a property of the exported function rather than a named export:\n\n```js\nimport copy from \u0027fast-copy\u0027;\n\ncopy(value, { maxDepth: 5000 });\n// detection: error instanceof copy.MaxDepthExceededError\n```\n\nIn legacy environments without `Object.setPrototypeOf`, `instanceof MaxDepthExceededError` cannot be supported; check `error.name === \u0027MaxDepthExceededError\u0027` or `error instanceof RangeError` instead.",
"id": "GHSA-jggr-w7fw-pc2j",
"modified": "2026-10-05T22:52:09Z",
"published": "2026-10-05T22:52:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/planttheidea/fast-copy/security/advisories/GHSA-jggr-w7fw-pc2j"
},
{
"type": "WEB",
"url": "https://github.com/planttheidea/fast-copy/pull/137"
},
{
"type": "WEB",
"url": "https://github.com/planttheidea/fast-copy/pull/138"
},
{
"type": "WEB",
"url": "https://github.com/planttheidea/fast-copy/pull/139"
},
{
"type": "WEB",
"url": "https://github.com/planttheidea/fast-copy/commit/359c00884ae8ae31f10925fd0e2fc66661db6cef"
},
{
"type": "WEB",
"url": "https://github.com/planttheidea/fast-copy/commit/caa7caace65767dfe252f0dc5115d82c99ca16b9"
},
{
"type": "WEB",
"url": "https://github.com/planttheidea/fast-copy/commit/dedf465e5329fbd149f13b53521af962d16ff8df"
},
{
"type": "PACKAGE",
"url": "https://github.com/planttheidea/fast-copy"
},
{
"type": "WEB",
"url": "https://github.com/planttheidea/fast-copy/releases/tag/v2.2.0"
},
{
"type": "WEB",
"url": "https://github.com/planttheidea/fast-copy/releases/tag/v3.1.0"
},
{
"type": "WEB",
"url": "https://github.com/planttheidea/fast-copy/releases/tag/v4.1.0"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "fast-copy: Stack exhaustion in fast-copy when copying deeply-nested values"
}
Mitigation
Ensure that an end condition will be reached under all logic conditions. The end condition may include checking against the depth of recursion and exiting with an error if the recursion goes too deep. The complexity of the end condition contributes to the effectiveness of this action.
Mitigation
Increase the stack size.
CAPEC-230: Serialized Data with Nested Payloads
Applications often need to transform data in and out of a data format (e.g., XML and YAML) by using a parser. It may be possible for an adversary to inject data that may have an adverse effect on the parser when it is being processed. Many data format languages allow the definition of macro-like structures that can be used to simplify the creation of complex structures. By nesting these structures, causing the data to be repeatedly substituted, an adversary can cause the parser to consume more resources while processing, causing excessive memory consumption and CPU utilization.
CAPEC-231: Oversized Serialized Data Payloads
An adversary injects oversized serialized data payloads into a parser during data processing to produce adverse effects upon the parser such as exhausting system resources and arbitrary code execution.