CVE-2026-3449
ADVISORY - githubSummary
Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang indefinitely. This can cause a control-flow leak that can lead to stalled requests, blocked workers, or degraded application availability.
Common Weakness Enumeration (CWE)
Incorrect Control Flow Scoping
Incorrect Control Flow Scoping
Use of Blocking Code in Single-threaded, Non-blocking Context
NIST
1.8
CVSS SCORE
4.8mediumGitHub
1.8
CVSS SCORE
1.9lowRed Hat
2.5
CVSS SCORE
4mediumChainguard
CGA-5jrv-6f42-c3ph
-
minimos
MINI-2wq9-vxff-c5h5
-
minimos
MINI-3frr-66jq-6p76
-
minimos
MINI-4fhq-mrwp-fj26
-
minimos
MINI-4fpm-mhh4-c98j
-
minimos
MINI-fcpj-x5vg-gxpm
-
minimos
MINI-fjpg-4jcx-4pwj
-
minimos
MINI-fq7h-x4px-cv49
-
minimos
MINI-g24m-5fpg-3397
-
minimos
MINI-jqm7-8v4j-h4gh
-
minimos
MINI-r555-wj8g-84p4
-
minimos
MINI-w96f-xjmf-733j
-
minimos
MINI-wcx4-79w3-37xv
-
minimos
MINI-wx23-rqhg-hw9w
-