Aug 22, 2026·6 min read·37 visits
Unauthenticated remote attackers can crash the Unleash server with a single ~10 KB nested JSON request, causing immediate and complete denial of service.
An unauthenticated remote denial of service vulnerability exists in the Unleash feature management platform. By submitting a crafted JSON payload containing deeply nested structures to an OpenAPI-validated endpoint, an attacker can trigger uncontrolled recursion within the error formatting module. This leads to a call-stack exhaustion (RangeError: Maximum call stack size exceeded) inside the Node.js runtime, causing the service to crash immediately without recovery.
Unleash is an open-source feature management platform implemented in Node.js. It coordinates feature flags across multiple environments, exposing APIs to both administrators and client applications. Among its public routes, several endpoints validate client-supplied parameters against structured OpenAPI definitions to enforce strict parameter schema requirements.
Under normal operations, when an API request fails schema validation, the application constructs a detailed error response containing the serialized representation of the problematic parameter. This mechanism utilizes endpoints such as /edge/validate or /edge/issue-token that do not require authentication, thereby exposing a significant attack surface to unauthorized network actors.
The vulnerability, classified under CWE-674 (Uncontrolled Recursion), resides within this error formatting pipeline. When a client submits a deeply nested but small JSON structure, the application's input validation failure code path executes a synchronous recursive parsing action. This process consumes the execution stack space and crashes the core process.
The underlying fault lies in the asymmetric handling of payload properties during the parsing and error validation phases. The Express body-parsing middleware restricts total request payload volume to prevent generic resource consumption attacks. However, it fails to enforce constraints on the maximum nesting depth of parsed JSON objects and arrays.
When a payload fails validation, the error handler retrieves the invalid property value using lodash.get and attempts to convert it to a string for debugging output. It passes the deeply nested structure directly to JSON.stringify to construct a descriptive feedback message. The native implementation of JSON.stringify in the V8 engine operates recursively over object and array tree structures.
Each level of array or object nesting requires the V8 engine to allocate a new stack frame on the call stack. Because the structure depth exceeds the physical limits of the call stack, the runtime encounters a synchronous RangeError: Maximum call stack size exceeded exception. This error is fatal.
Because this synchronous exception occurs within Express's internal error generation routine rather than the standard request-handling logic, it bypasses the standard middleware-level exception catch blocks. Lacking a global uncaughtException listener configured to gracefully drop the connection, the entire Node.js runtime terminates with an exit code of 1.
The vulnerability was mitigated in commit b0e4da63249a9403bc209e0581db223326cb8dcf by introducing an explicit safe serialization helper. This helper wraps the invocation of the recursive encoder in a try-catch block, preventing the synchronous exception from bubbling up to the runtime process manager.
// Patched safe stringification helper
const safeStringify = (value: unknown): string => {
try {
return JSON.stringify(value);
} catch {
// Fallback string returned when stack overflow is triggered
return '[value too large or deeply nested to display]';
}
};The patch modifies critical code paths inside src/lib/error/bad-data-error.ts and src/lib/routes/util.ts. All previous direct assignments calling JSON.stringify on user-controlled input properties now execute via the safeStringify function wrapper.
diff --git a/src/lib/error/bad-data-error.ts b/src/lib/error/bad-data-error.ts
--- a/src/lib/error/bad-data-error.ts
+++ b/src/lib/error/bad-data-error.ts
@@ -72,7 +80,7 @@ const genericErrorMessage = (
propertyValue: object,
errorMessage: string = 'is invalid',
) => {
- const youSent = JSON.stringify(propertyValue);
+ const youSent = safeStringify(propertyValue);
const message = `The \`${propertyName}\` property ${errorMessage}. You sent ${youSent}.`;While wrapping the serialization prevents the immediate process termination, it represents a reactive mitigation rather than a structural defense. The engine still spends computational resources parsing the deeply nested object in the body-parser before rejecting it, meaning that very high-frequency request rates could still impact CPU utilization.
Exploitation of this vulnerability requires only network access to an unauthenticated endpoint governed by OpenAPI schema validation rules. The attacker does not need credentials, active session tokens, or specific configuration states to execute the attack.
An attacker constructs a payload consisting of nested arrays or objects. A nesting level of 5,000 is generally sufficient to exceed the default call stack limits of standard Node.js V8 execution environments. This payload occupies approximately 10 KB, allowing it to easily bypass common web application firewall restrictions governing maximum body size.
Upon transmitting the payload to an endpoint like POST /edge/validate, the application attempts to validate the input. Because the input does not match the schema, the validator initiates the error formatter. The error formatter calls the serialization engine, which exceeds the stack size and immediately crashes the service.
# Conceptual representation of a single-request crash trigger
python3 -c "print('[' * 5000 + '1' + ']' * 5000)" > dos_payload.json
curl -s -X POST -H "Content-Type: application/json" \
-d @dos_payload.json \
http://example-unleash-target.local/edge/validateThe security impact of CVE-2026-63462 is restricted to the Availability domain. There is no risk of Confidentiality compromise, data exposure, or unauthorized modification of application configuration data. The CVSS vector string is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H reflecting a score of 7.5.
Because the backend execution environment runs as a single-threaded process in Node.js, the failure of the primary process instantly terminates all concurrent active user connections. In clustered configurations or containers lacking active auto-restart mechanisms, a single request can permanently disable service availability.
If the server runs within an orchestrated container cluster (such as Kubernetes or ECS) configured with auto-recovery, the container is automatically scheduled for restart. However, an attacker can maintain a persistent outage by repeatedly transmitting the trigger payload at a rate matching the container recovery cycle.
The primary resolution is to upgrade Unleash to a patched version. Administrators should identify and apply updates to transition their environments past the affected version boundaries. The issue is resolved in versions 7.5.2, 7.6.5, and 8.0.2.
If upgrading is not immediately possible, deploy a defensive configuration change or rule on intermediate reverse proxies or Web Application Firewalls (WAF). Setting a rule that rejects JSON bodies with an object or array nesting depth greater than 50 protects the application from encountering deep inputs.
Additionally, verify that the Unleash node processes run under a supervisor that automatically recovers from uncaught exceptions, such as PM2 or systemd. While this does not prevent the processing thread crash, it limits the offline duration of the service following isolated exploit attempts.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H| Product | Affected Versions | Fixed Version |
|---|---|---|
Unleash Server Unleash | < 7.5.2 | 7.5.2 |
Unleash Server Unleash | >= 7.6.0, < 7.6.5 | 7.6.5 |
Unleash Server Unleash | >= 8.0.0, < 8.0.2 | 8.0.2 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-674 (Uncontrolled Recursion) |
| Attack Vector | Network |
| CVSS Score | 7.5 (High) |
| Exploit Status | Proof of Concept available |
| Impact | Complete Denial of Service (DoS) |
| KEV Status | Not listed |
The software directs execution into a function that calls itself recursively without an adequate exit condition, leading to stack overflow.
A vulnerability in the Client-Side Field-Level Encryption (CSFLE) component of the MongoDB Python Driver (PyMongo) allows an attacker with database write access to trigger local Unix domain socket connections. By manipulating the Key Management Service (KMS) endpoint configuration inside the key vault collection to end with a '.sock' extension, an attacker forces the application to perform a Server-Side Request Forgery (SSRF) against internal Unix domain sockets.
A critical double-free vulnerability exists in the Transparent Inter-Process Communication (TIPC) module of the Linux kernel, specifically within the fragment reassembly implementation in `tipc_buf_append()`. This vulnerability can be triggered locally or remotely to cause kernel heap corruption, leading to local privilege escalation or denial of service.
CVE-2026-72137 is a critical double-free vulnerability in the Linux kernel's XFRM (IPsec) subsystem. The vulnerability occurs when the kernel attempts to send NAT keepalive packets over UDP. Under specific transmission failure conditions, both the downstream networking stack and the upstream keepalive dispatcher attempt to free the same socket buffer (sk_buff) structure, leading to kernel memory corruption, denial of service, or potential local privilege escalation.
A critical host injection vulnerability exists in PyMongo's connection string parser prior to version 4.18.2. The parser globally decodes percent-encoded characters in the host portion before splitting on delimiters, allowing attackers to inject arbitrary servers into the database client's connection pool.
An integer overflow vulnerability exists in PyMongo's bundled C extension (bson/buffer.c) when serializing abnormally large documents. Due to compiler optimizations utilizing standard C Undefined Behavior rules, memory overflow validation checks are completely removed during compilation, enabling an attacker to trigger a heap-based out-of-bounds write.
CVE-2026-102827 is an argument injection bypass vulnerability in the node.js simple-git package where the default blockUnsafeOperationsPlugin fails to detect abbreviated Git command options. Attackers can bypass validations using prefixes like --receive-p or --exe, which native Git subsequently expands to dangerous options, leading to remote command execution.