PatchSiren cyber security CVE debrief
CVE-2026-32141 WebReflection CVE debrief
CVE-2026-32141 is a vulnerability in the Flatted circular JSON parser, which can lead to a stack overflow and crash the Node.js process. The vulnerability is caused by an unbounded recursion depth in the parse() function's revive() phase when given a crafted payload with deeply nested or self-referential $ indices. This issue was fixed in version 3.4.0. Users of Flatted prior to 3.4.0 are advised to upgrade to the latest version. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The CVE was published on March 12, 2026, and modified on June 30, 2026.
- Vendor
- WebReflection
- Product
- flatted
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-12
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-03-12
- Advisory updated
- 2026-09-04
Who should care
Developers and administrators using the Flatted library in their Node.js applications should be aware of this vulnerability and take steps to mitigate it. This includes upgrading to version 3.4.0 or later, and reviewing their applications for potential exposure. Additionally, users of Red Hat products may be affected, as indicated by the presence of several Red Hat errata references.
Technical summary
The Flatted library is a circular JSON parser for Node.js. Prior to version 3.4.0, the library's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. However, when given a crafted payload with deeply nested or self-referential $ indices, the recursion depth becomes unbounded, leading to a stack overflow that crashes the Node.js process. This vulnerability can be exploited by an attacker to cause a denial-of-service (DoS) attack. The vulnerability is characterized by a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a high severity. The issue was addressed in version 3.4.0.
Defensive priority
This vulnerability has a high severity score and can be exploited to cause a denial-of-service (DoS) attack. Therefore, it is essential to prioritize mitigation efforts, especially for applications that use the Flatted library in a production environment.
Recommended defensive actions
- Upgrade to Flatted version 3.4.0 or later
- Review applications for potential exposure and test for vulnerability
- Apply patches or updates provided by vendors, such as Red Hat
- Monitor applications for suspicious activity
- Consider implementing additional security measures, such as input validation and error handling
Evidence notes
The CVE-2026-32141 vulnerability was published on March 12, 2026, and modified on June 30, 2026. The vulnerability is caused by an issue in the Flatted library, which is used for parsing circular JSON in Node.js applications. Several sources, including the NVD and Red Hat, have documented this vulnerability and provided guidance on mitigation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-32141 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-32141
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-32141 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32141
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/WebReflection/flatted/commit/7eb65d857e1a40de11c47461cdbc8541449f0606
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/WebReflection/flatted/pull/88
[email protected] - Issue Tracking, Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/WebReflection/flatted/security/advisories/GHSA-25h7-pfq9-p65f
[email protected] - Exploit, Patch, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:13826
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:21772
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:5807
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:9742
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.