CVE-2026-32141: flatted: Unbounded recursion DoS in parse() revive phase
Summary
flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the Node.js process.
Impact
Denial of Service (DoS). Any application that passes untrusted input to flatted.parse() can be crashed by an unauthenticated attacker with a single request.
flatted has ~87M weekly npm downloads and is used as the circular-JSON serialization layer in many caching and logging libraries.
Proof of Concept
javascript const flatted = require('flatted');
// Build deeply nested circular reference chain const depth = 20000; const arr = new Array(depth + 1); arr[0] = '{"a":"1"}'; for (let i = 1; i <= depth; i++) { arr[i] = {"a":"${i + 1}"}; } arr[depth] = '{"a":"leaf"}';
const payload = JSON.stringify(arr); flatted.parse(payload); // RangeError: Maximum call stack size exceeded
Fix
The maintainer has already merged an iterative (non-recursive) implementation in PR #88, converting the recursive revive() to a stack-based loop.
Affected Versions
All versions prior to the PR #88 fix.
Other sources
flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the Node.js process. This vulnerability is fixed in 3.4.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/flattedto a version that resolves this vulnerability.Fixed in 3.4.0 - Upgrade
Upgrade
flattedto a version that resolves this vulnerability.Fixed in 3.4.0Patch PR #88
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32141?
CVE-2026-32141 is classified as a denial-of-service vulnerability due to unbounded recursion.
How do I fix CVE-2026-32141?
To fix CVE-2026-32141, upgrade to flatted version 3.4.0 or later.
What causes CVE-2026-32141?
CVE-2026-32141 is caused by the parse() function in flatted using a recursive method to handle deeply nested or self-referential JSON.
Which versions of flatted are affected by CVE-2026-32141?
Versions of flatted prior to 3.4.0 are affected by CVE-2026-32141.
How can CVE-2026-32141 affect my application?
Exploiting CVE-2026-32141 can lead to denial-of-service conditions in applications using vulnerable versions of the flatted library.