CVE-2026-3449
Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang indefinitely. This can cause a control-flow leak that can lead to stalled requests, blocked workers, or degraded application availability.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.11%
- CWE
- CWE-705
- Published
- 2026-03-03
- Last modified
- 2026-05-04
Affected products
- n/a @tootallnate/once
- npm @tootallnate/once
Weakness type
Related vulnerabilities
- CVE-2026-55537 — PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
- CVE-2026-45819 — baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or...
- CVE-2026-10271 — a4m4 Student-Management-System Admin Endpoint admin redirect
- CVE-2026-3264 — go2ismail Free-CRM Administrative redirect
- CVE-2026-3262 — go2ismail Asp.Net-Core-Inventory-Order-Management-System Administrative redirect
- CVE-2025-53856 — TMM vulnerability
- CVE-2025-9848 — ScriptAndTools Real Estate Management System userlist.php redirect