CVE-2026-32141

high Red Hat
CVSS v3 Base Score
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published: March 12, 2026
Last Modified: March 12, 2026
Vendor: Red Hat
Source: REDHAT

Description

A denial of service flaw has been discovered in the flatted npm library. flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the Node.js process.

CWE

CWE-770

Affected Products

Cryostat 4Logging Subsystem for Red Hat OpenShiftRed Hat 3scale API Management Platform 2Red Hat AMQ Broker 7Red Hat Ansible Automation Platform 2Red Hat build of Apicurio Registry 2Red Hat build of OptaPlanner 8Red Hat Data Grid 8Red Hat Directory Server 11Red Hat Directory Server 12

References