deepmerge-ts versions earlier than 8.0.0 contain an uncontrolled-recursion flaw in the deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs. During recursive record merging, these APIs do not maintain visited-object or visited-object-pair state. If both merge inputs contain self-references at the same property path, the implementation repeatedly processes the same pair until Node.js terminates the recursion with a maximum-call-stack RangeError.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone JavaScript proof-of-concept for CVE-2026-40345 / GHSA-ggr8-5vv4-36mx affecting deepmerge-ts versions prior to 8.0.0. It is not part of a larger exploit framework. The repo contains two functional scripts: poc.mjs and scanner.mjs, plus package metadata and a detailed README. The main exploit capability is denial of service through uncontrolled recursion. poc.mjs imports deepmerge and deepmergeInto from deepmerge-ts, creates two separate self-referential objects via recursiveRecord(), and invokes the merge APIs on them. Because affected versions do not track previously seen object pairs or detect cycles, the merge repeatedly revisits the same left/right pair through the self property until Node.js throws a RangeError for maximum call stack size exceeded. The script catches that specific exception and reports successful reproduction. This is a local PoC rather than a remote exploit by itself. The README clearly explains that remote exploitability depends on surrounding application logic: plain JSON alone does not create cyclic graphs, so an application must hydrate, preserve, or reconstruct object references from attacker-controlled input before calling deepmerge-ts. It provides an example HTTP route POST /merge where user input with self:true is transformed into self-referential objects, making a single request sufficient to crash a worker if exceptions are uncaught. scanner.mjs is a companion detection utility, not the exploit itself. It recursively scans a target directory for package.json, package-lock.json, npm-shrinkwrap.json, and pnpm-lock.yaml, then flags vulnerable or review-needed deepmerge-ts dependency references. It supports optional JSON output and exits with code 1 when vulnerable findings are present. Repository structure: README.md documents the vulnerability, exploitation conditions, remediation, and usage; poc.mjs demonstrates the crash; scanner.mjs identifies affected dependency references; package.json and package-lock.json pin deepmerge-ts 7.1.6 for reproduction. Overall, the repository’s purpose is to reproduce and validate a stack exhaustion DoS in deepmerge-ts and help locate affected installations.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A denial-of-service vulnerability in the deepmerge-ts TypeScript library where recursive merging of self-referential object graphs can cause unbounded recursion and a stack overflow, crashing the Node.js process.
A high-severity denial-of-service vulnerability in deepmerge-ts versions before 8.0.0. Merging attacker-controlled recursive object graphs can synchronously crash an affected Node.js process or trigger repeated worker restarts; plain JSON alone cannot create the required recursive graph.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.