Sceawere
Vulnerability Detail
CVE-2026-104182UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
stream-json Quadratic Complexity Denial of Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.2
- Creation Date
- 1d ago
- Vendor
- uhop
- Product
- stream-json
- Attack Type
- CWE-407: Inefficient Algorithmic Complexity
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.2",
"pubDate": "2026-10-01T21:17:19.003Z",
"pubdate": "2026-10-01T21:17:19.003Z",
"executiveSummary": "The stream-json library contains a performance vulnerability in its JSONC parsing components, specifically within the parser and verifier logic. The issue manifests as a quadratic time complexity condition when processing crafted JSONC input containing fragmented multi-chunk comments.\nThis vulnerability is classified as an Algorithmic Complexity Denial of Service (DoS). By delivering a large, valid JSONC comment across a series of small, fragmented data chunks, an attacker can induce excessive CPU consumption.\nThe primary impact is the exhaustion of available CPU resources, leading to the stalling of the Node.js event loop, which effectively causes a service-wide denial of availability.\nThe affected components are limited to the JSONC parser (stream-json/jsonc/parser.js) and the JSONC verifier (stream-json/jsonc/verifier.js). Plain JSON parsing functionality is unaffected by this flaw.\nWhile the maintainer notes that the attack vector is typically constrained to local configuration files, any application that permits user-controlled or untrusted input to be processed by the JSONC parser remains at risk.\nExploitation requires no authentication, provided the attacker has the ability to submit or influence the JSONC input stream processed by the application.",
"technicalDetails": "The root cause of the vulnerability lies in the state management logic within the JSONC parser and verifier components of the stream-json library. When processing JSONC input that is split across multiple small chunks, the parser exhibits inefficient behavior during comment scanning.\nSpecifically, when a block or line comment spans multiple input chunks, the parser logic improperly resets the comment-terminator scan to the initial opening slash of the comment sequence. Despite this reset, the parser retains the previously accumulated comment buffer, leading to redundant scanning of the same data multiple times as the input is processed chunk-by-chunk.\nThis behavior results in quadratic complexity (O(n^2)) relative to the length of the comment. As the number of chunks increases, the cumulative number of operations grows exponentially, forcing the Node.js event loop to dedicate disproportionate resources to string processing and character scanning rather than handling I/O or other tasks.\nThe attack flow follows a sequential pattern: 1) The attacker transmits a maliciously crafted JSONC stream consisting of a very large comment sequence. 2) The attacker breaks this comment into numerous small, sequential chunks. 3) Upon receiving each chunk, the library attempts to re-parse the comment state from the start of the comment, repeatedly traversing the existing buffer. 4) The CPU utilization spikes as the parser performs redundant iterations over the comment content for every fragment received. 5) The Node.js single-threaded event loop becomes blocked, causing the entire application to become unresponsive to new requests or internal callbacks.\nThis issue affects all versions of the stream-json library prior to 3.6.0. The vulnerability is restricted to the JSONC parser and verifier modules. The standard JSON parser avoids this issue because it consumes and discards string and numerical data without triggering the state-reset behavior identified in the JSONC-specific code paths. There are no authentication or privilege requirements for this exploit, as it targets the fundamental parsing logic of the library, making it a highly effective DoS vector if the application exposes JSONC-based input endpoints to external or untrusted users."
}