Description
Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang indefinitely.
Recommendation
Update the @tootallnate/once package to the latest compatible version. Followings are version details:
Affected version(s): **< 2.0.1 >= 3.0.0, < 3.0.1** Patched version(s): **2.0.1 3.0.1**
References
Related Issues
- OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding - CVE-2026-30920
- CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function - CVE-2026-26861
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- Backstage vulnerable to potential reading of SCM URLs using built in token - CVE-2026-29185
You might also like:
- Tags:
- npm
- @tootallnate/once
Anything's wrong? Let us know Last updated on May 21, 2026


