Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
WebReflection flatted — flatted: Unbounded recursion DoS in parse() revive phase
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N N H 7.5 .0081 54.0 —
AFFECTED
Product Versions Fixed
flatted < 3.4.0 – —
TIMELINE
Mar 10 Reserved by GitHub_M
Mar 12 Published (CNA: GitHub_M)
Aug 4 EXPLOIT PUBLISHED — CVE-2026-32141 (WebReflection flatted). Public exploit reference added.
Description
flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the Node.js process. This vulnerability is fixed in 3.4.0.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| March 10, 2026 | Reserved | Reserved by GitHub_M |
| March 12, 2026 | Published | Published (CNA: GitHub_M) |
| August 4, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-32141 (WebReflection flatted). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| WebReflection | flatted | — | < 3.4.0 | — |
References (14)
- https://access.redhat.com/errata/RHSA-2026:13826 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:21772 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:34342 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:36651 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:40118 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:40945 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:5807 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/errata/RHSA-2026:9742 [vendor-advisory, x_refsource_REDHAT]
- https://access.redhat.com/security/cve/CVE-2026-32141 [vdb-entry, x_refsource_REDHAT]
- https://bugzilla.redhat.com/show_bug.cgi?id=2447083 [issue-tracking, x_refsource_REDHAT]
- https://github.com/WebReflection/flatted/commit/7eb65d857e1a40de11c47461cdbc8541449f0606 [x_refsource_MISC]
- https://github.com/WebReflection/flatted/pull/88 [x_refsource_MISC]
- https://github.com/WebReflection/flatted/security/advisories/GHSA-25h7-pfq9-p65f [x_refsource_CONFIRM]
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32141.json [x_sadp-csaf-vex]
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-32141 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.