CVE-2026-32141
highCVSS v3 Base Score
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.0%
Exploitation probability in 30 days
Top 89% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
None
Integrity
None
Availability
High
Published: March 12, 2026 (63 days ago)
Last Modified: March 12, 2026
Vendor: Red Hat
Source: REDHAT
Vulnerability Report
Generated by CyberWatcher
Description
A denial of service flaw has been discovered in the flatted npm library. flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the Node.js process.
CWE
CWE-770Affected Products
Cryostat 4Logging Subsystem for Red Hat OpenShiftRed Hat 3scale API Management Platform 2Red Hat AMQ Broker 7Red Hat Ansible Automation Platform 2Red Hat build of Apicurio Registry 2Red Hat build of OptaPlanner 8Red Hat Data Grid 8Red Hat Directory Server 11Red Hat Directory Server 12