GHSA-JGGR-W7FW-PC2J

Vulnerability from github – Published: 2026-10-05 22:52 – Updated: 2026-10-05 22:52
VLAI
Summary
fast-copy: Stack exhaustion in fast-copy when copying deeply-nested values
Details

Summary

fast-copy traverses values recursively with no bound on depth. Copying a sufficiently deeply-nested value exhausts the JavaScript call stack and throws a native RangeError: Maximum call stack size exceeded from inside the library.

Details

Both copy and copyStrict recurse once per level of nesting. The value does not need to be circular (circular references were already handled correctly via an internal cache) and it does not need to be large. A plain object nested a few thousand levels deep is only a few kilobytes of equivalent JSON.

Measured depths at which copying begins to fail (Node.js, V8; the exact ceiling varies with JIT state and the stack available to the environment):

Call Last depth that copies successfully
copy(object) 2811
copy(array) 3983
copyStrict(object) 1874
copyStrict(array) 1874

JSON.parse is iterative and parses deeply-nested input without difficulty, so a payload that deserializes cleanly can fail in a subsequent copy call.

Impact

The failure is a synchronous, catchable RangeError confined to the copy call that received the value. There are no memory safety concerns, no data exposure, and no effect on state outside that call. In a typical server the result is a failed request rather than a failed process.

Applications that call copy on externally-supplied data, such as request bodies, cached payloads, merged configuration, etc., do not expect a clone helper to throw may surface this as an unhandled error.

Patches

Fixed in 4.1.0, and backported to 3.1.0 and 2.2.0 so that every major line has a patch available without requiring a breaking upgrade.

Traversal is now bounded by a maxDepth option, defaulting to 1000, which sits below the native limit in standard environments. Exceeding it throws MaxDepthExceededError, which carries the limit that was exceeded and extends RangeError so existing handling continues to match.

The limit is configurable for consumers with legitimately deep data. On 3.x and 4.x it is set when creating a copier:

import { createCopier } from 'fast-copy';

export const copy = createCopier({ maxDepth: 5000 });

On 2.x it is passed per call, and the error is a property of the exported function rather than a named export:

import copy from 'fast-copy';

copy(value, { maxDepth: 5000 });
// detection: error instanceof copy.MaxDepthExceededError

In legacy environments without Object.setPrototypeOf, instanceof MaxDepthExceededError cannot be supported; check error.name === 'MaxDepthExceededError' or error instanceof RangeError instead.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "fast-copy"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.0.0"
            },
            {
              "fixed": "4.1.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "npm",
        "name": "fast-copy"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.0.0"
            },
            {
              "fixed": "3.1.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "npm",
        "name": "fast-copy"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.2.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-674"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-05T22:52:09Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "## Summary\n\n`fast-copy` traverses values recursively with no bound on depth. Copying a sufficiently deeply-nested value exhausts the JavaScript call stack and throws a native `RangeError: Maximum call stack size exceeded` from inside the library.\n\n## Details\n\nBoth `copy` and `copyStrict` recurse once per level of nesting. The value does not need to be circular (circular references were already handled correctly via an internal cache) and it does not need to be large. A plain object nested a few thousand levels deep is only a few\nkilobytes of equivalent JSON.\n\nMeasured depths at which copying begins to fail (Node.js, V8; the exact ceiling varies with JIT state and the stack available to the environment):\n\n| Call                 | Last depth that copies successfully |\n| -------------------- | ----------------------------------- |\n| `copy(object)`       | 2811                                |\n| `copy(array)`        | 3983                                |\n| `copyStrict(object)` | 1874                                |\n| `copyStrict(array)`  | 1874                                |\n\n`JSON.parse` is iterative and parses deeply-nested input without difficulty, so a payload that deserializes cleanly can fail in a subsequent `copy` call.\n\n## Impact\n\nThe failure is a synchronous, catchable `RangeError` confined to the `copy` call that received the value. There are no memory safety concerns, no data exposure, and no effect on state outside that call. In a typical server the result is a failed request rather than a failed process.\n\nApplications that call `copy` on externally-supplied data, such as request bodies, cached payloads, merged configuration, etc., do not expect a clone helper to throw may surface this as an unhandled error.\n\n## Patches\n\nFixed in 4.1.0, and backported to 3.1.0 and 2.2.0 so that every major line has a patch available without requiring a breaking upgrade.\n\nTraversal is now bounded by a `maxDepth` option, defaulting to `1000`, which sits below the native limit in standard environments. Exceeding it throws `MaxDepthExceededError`, which carries the limit that was exceeded and extends `RangeError` so existing handling continues to match.\n\nThe limit is configurable for consumers with legitimately deep data. On `3.x` and `4.x` it is set when creating a copier:\n\n```js\nimport { createCopier } from \u0027fast-copy\u0027;\n\nexport const copy = createCopier({ maxDepth: 5000 });\n```\n\nOn `2.x` it is passed per call, and the error is a property of the exported function rather than a named export:\n\n```js\nimport copy from \u0027fast-copy\u0027;\n\ncopy(value, { maxDepth: 5000 });\n// detection: error instanceof copy.MaxDepthExceededError\n```\n\nIn legacy environments without `Object.setPrototypeOf`, `instanceof MaxDepthExceededError` cannot be supported; check `error.name === \u0027MaxDepthExceededError\u0027` or `error instanceof RangeError` instead.",
  "id": "GHSA-jggr-w7fw-pc2j",
  "modified": "2026-10-05T22:52:09Z",
  "published": "2026-10-05T22:52:09Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/planttheidea/fast-copy/security/advisories/GHSA-jggr-w7fw-pc2j"
    },
    {
      "type": "WEB",
      "url": "https://github.com/planttheidea/fast-copy/pull/137"
    },
    {
      "type": "WEB",
      "url": "https://github.com/planttheidea/fast-copy/pull/138"
    },
    {
      "type": "WEB",
      "url": "https://github.com/planttheidea/fast-copy/pull/139"
    },
    {
      "type": "WEB",
      "url": "https://github.com/planttheidea/fast-copy/commit/359c00884ae8ae31f10925fd0e2fc66661db6cef"
    },
    {
      "type": "WEB",
      "url": "https://github.com/planttheidea/fast-copy/commit/caa7caace65767dfe252f0dc5115d82c99ca16b9"
    },
    {
      "type": "WEB",
      "url": "https://github.com/planttheidea/fast-copy/commit/dedf465e5329fbd149f13b53521af962d16ff8df"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/planttheidea/fast-copy"
    },
    {
      "type": "WEB",
      "url": "https://github.com/planttheidea/fast-copy/releases/tag/v2.2.0"
    },
    {
      "type": "WEB",
      "url": "https://github.com/planttheidea/fast-copy/releases/tag/v3.1.0"
    },
    {
      "type": "WEB",
      "url": "https://github.com/planttheidea/fast-copy/releases/tag/v4.1.0"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "fast-copy: Stack exhaustion in fast-copy when copying deeply-nested values"
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…