Allocation of Resources Without Limits or Throttling in nest - #VU150165
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the TCP transport's JsonSocket partial-packet buffering when a peer sends a partial framed message and leaves the connection open. A remote attacker can send a declared message length with a partial payload and keep connections open to cause a denial of service.
Only applications using Transport.TCP with a port reachable by an untrusted peer are affected.