Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-25h7-pfq9-p65f | flatted vulnerable to unbounded recursion DoS in parse() revive phase |
Thu, 19 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:webreflection:flatted:*:*:*:*:*:node.js:*:* |
Fri, 13 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 13 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webreflection
Webreflection flatted |
|
| Vendors & Products |
Webreflection
Webreflection flatted |
Thu, 12 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the Node.js process. This vulnerability is fixed in 3.4.0. | |
| Title | flatted: Unbounded recursion DoS in parse() revive phase | |
| Weaknesses | CWE-674 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-13T16:20:19.201Z
Reserved: 2026-03-10T22:19:36.546Z
Link: CVE-2026-32141
Updated: 2026-03-13T16:20:10.284Z
Status : Analyzed
Published: 2026-03-12T18:16:25.837
Modified: 2026-03-19T21:07:24.717
Link: CVE-2026-32141
OpenCVE Enrichment
Updated: 2026-03-20T15:48:38Z
Github GHSA