mediumVulnerability

GHSA-jggr-w7fw-pc2j

## Summary `fast-copy` traverses values recursively with no bound on depth. Copying a sufficiently deeply-nested value exhausts the JavaScript call stack and throws a native `RangeError: Maximum call stack size exceeded` from inside the library. ## Details Both `copy` and `copyStrict` recurse once per level of nesting. The value does not need to be circular (circular references were already handled correctly via an internal cache) and it does not need to be large. A plain object nested a few thousand levels deep is only a few kilobytes of equivalent JSON. Measured depths at which copying begins to fail (Node.js, V8; the exact ceiling varies with JIT state and the stack available to the environment): | Call | Last depth that copies successfully | | -------------------- | ----------------------------------- | | `copy(object)` | 2811 | | `copy(array)` | 3983 | | `copyStrict(object)` | 1874 | | `copyStrict(array)` | 1874 | `JSON.parse` is iterative and parses deeply-nested input without difficulty, so a payload that deserializes cleanly can fail in a subsequent `copy` call. ## Impact The failure is a synchronous, catchable `RangeError` confined to the `copy` call that received the value. There are no memory safety concerns, no data exposure, and no effect on state outside that call. In a typical server the result is a failed request rather than a failed process. Applications that call `copy` on externally-supplied data, such as request bodies, cached payloads, merged configuration, etc., do not expect a clone helper to throw may surface this as an unhandled error. ## Patches Fixed in 4.1.0, and backported to 3.1.0 and 2.2.0 so that every major line has a patch available without requiring a breaking upgrade. Traversal is now bounded by a `maxDepth` option, defaulting to `1000`, which sits below the native li

Properties

ghsa_id
GHSA-jggr-w7fw-pc2j
severity
medium
summary
fast-copy: Stack exhaustion in fast-copy when copying deeply-nested values
last_source
GitHub Advisory Database
cve_id
GHSA-jggr-w7fw-pc2j
signal_observed_at
2026-10-05T22:59:07+00:00
is_ghsa_only
true
retrieved_at
2026-10-05T22:59:07+00:00
ghsa_published
2026-10-05T22:52:09Z
source_url
https://github.com/advisories/GHSA-jggr-w7fw-pc2j
ghsa_updated
2026-10-05T22:52:12Z

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Uncontrolled Recursion

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/fast-copy

AFFECTS (1)

→[Software]npm/fast-copy

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-jggr-w7fw-pc2j — Ninja Signal Threat Intelligence | Ninja Signal