PT-2026-22719 · Unknown · @Tootallnate/Once

Nanak-Singh

·

Published

2026-03-03

·

Updated

2026-05-19

·

CVE-2026-3449

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions @tootallnate/once versions prior to 3.0.1
Description The package @tootallnate/once versions prior to 3.0.1 are susceptible to an issue with incorrect control flow scoping in promise resolving when the AbortSignal option is utilized. When the signal is aborted, the Promise remains in a permanently pending state, leading to indefinite hanging of any await or .then() operations. This control-flow leak can potentially result in stalled requests, blocked workers, or reduced application availability.
Recommendations Update @tootallnate/once to version 3.0.1 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-3449
GHSA-VPQ2-C234-7XJ6
OPENSUSE-SU-2026:10290-1
OPENSUSE-SU-2026:10429-1

Affected Products

@Tootallnate/Once