Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vpq2-c234-7xj6 | @tootallnate/once vulnerable to Incorrect Control Flow Scoping |
Wed, 04 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tootallnate
Tootallnate once |
|
| Vendors & Products |
Tootallnate
Tootallnate once |
Wed, 04 Mar 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | @tootallnate/once: @tootallnate/once: Denial of Service due to incorrect control flow scoping with AbortSignal | |
| Weaknesses | CWE-1322 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 03 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Mar 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang indefinitely. This can cause a control-flow leak that can lead to stalled requests, blocked workers, or degraded application availability. | |
| Weaknesses | CWE-705 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2026-05-04T05:23:47.062Z
Reserved: 2026-03-02T17:14:02.496Z
Link: CVE-2026-3449
Updated: 2026-03-03T15:31:41.721Z
Status : Awaiting Analysis
Published: 2026-03-03T05:17:25.017
Modified: 2026-04-29T01:00:01.613
Link: CVE-2026-3449
OpenCVE Enrichment
Updated: 2026-04-17T13:30:19Z
Github GHSA