PT-2026-22719 · Unknown · @Tootallnate/Once
Nanak-Singh
·
Published
2026-03-03
·
Updated
2026-05-19
·
CVE-2026-3449
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
@tootallnate/once versions prior to 3.0.1
Description
The package @tootallnate/once versions prior to 3.0.1 are susceptible to an issue with incorrect control flow scoping in promise resolving when the AbortSignal option is utilized. When the signal is aborted, the Promise remains in a permanently pending state, leading to indefinite hanging of any
await or .then() operations. This control-flow leak can potentially result in stalled requests, blocked workers, or reduced application availability.Recommendations
Update @tootallnate/once to version 3.0.1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Tootallnate/Once