PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-32141 WebReflection CVE debrief

CVE-2026-32141 is a vulnerability in the Flatted circular JSON parser, which can lead to a stack overflow and crash the Node.js process. The vulnerability is caused by an unbounded recursion depth in the parse() function's revive() phase when given a crafted payload with deeply nested or self-referential $ indices. This issue was fixed in version 3.4.0. Users of Flatted prior to 3.4.0 are advised to upgrade to the latest version. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The CVE was published on March 12, 2026, and modified on June 30, 2026.

Vendor
WebReflection
Product
flatted
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-12
Original CVE updated
2026-09-04
Advisory published
2026-03-12
Advisory updated
2026-09-04

Who should care

Developers and administrators using the Flatted library in their Node.js applications should be aware of this vulnerability and take steps to mitigate it. This includes upgrading to version 3.4.0 or later, and reviewing their applications for potential exposure. Additionally, users of Red Hat products may be affected, as indicated by the presence of several Red Hat errata references.

Technical summary

The Flatted library is a circular JSON parser for Node.js. Prior to version 3.4.0, the library's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. However, when given a crafted payload with deeply nested or self-referential $ indices, the recursion depth becomes unbounded, leading to a stack overflow that crashes the Node.js process. This vulnerability can be exploited by an attacker to cause a denial-of-service (DoS) attack. The vulnerability is characterized by a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a high severity. The issue was addressed in version 3.4.0.

Defensive priority

This vulnerability has a high severity score and can be exploited to cause a denial-of-service (DoS) attack. Therefore, it is essential to prioritize mitigation efforts, especially for applications that use the Flatted library in a production environment.

Recommended defensive actions

  • Upgrade to Flatted version 3.4.0 or later
  • Review applications for potential exposure and test for vulnerability
  • Apply patches or updates provided by vendors, such as Red Hat
  • Monitor applications for suspicious activity
  • Consider implementing additional security measures, such as input validation and error handling

Evidence notes

The CVE-2026-32141 vulnerability was published on March 12, 2026, and modified on June 30, 2026. The vulnerability is caused by an issue in the Flatted library, which is used for parsing circular JSON in Node.js applications. Several sources, including the NVD and Red Hat, have documented this vulnerability and provided guidance on mitigation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-32141 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-32141

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-32141 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32141

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/WebReflection/flatted/commit/7eb65d857e1a40de11c47461cdbc8541449f0606

    [email protected] - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/WebReflection/flatted/pull/88

    [email protected] - Issue Tracking, Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/WebReflection/flatted/security/advisories/GHSA-25h7-pfq9-p65f

    [email protected] - Exploit, Patch, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:13826

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:21772

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:5807

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:9742

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.