Description
stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0.
Published: 2026-10-01
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1322
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 01 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Uhop
Uhop stream-json
Vendors & Products Uhop
Uhop stream-json

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0.
Title stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Uhop Stream-json
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T20:15:39.108Z

Reserved: 2026-10-01T18:54:15.118Z

Link: CVE-2026-104182

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T21:17:19.003

Modified: 2026-10-02T18:47:49.947

Link: CVE-2026-104182

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-01T20:15:39Z

Links: CVE-2026-104182 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:15Z

Weaknesses