Description
stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0.
Published: 2026-10-01
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the stream-json library causes the JSONC parser and verifier to repeatedly scan the full accumulated comment whenever a block or line comment spans an input chunk. This causes quadratic CPU consumption and can stall the Node.js event loop, effectively denying service to the application. The weakness falls under CWE‑407: Incorrect Resource Exhaustion Evaluation.

Affected Systems

The affected product is uhop's stream-json. Versions prior to 3.6.0 are vulnerable; the fix is included in release 3.6.0 and later.

Risk and Exploitability

The CVSS score of 6.2 reflects a moderate severity. Exploit likelihood is not quantified due to unavailable EPSS data, and the vulnerability is not listed in the CISA KEV catalog. The documented attack vector is local, meaning that an attacker would need to supply JSONC input from a locally controlled or user‑managed configuration. No known public exploits are reported as of this analysis.

Generated by OpenCVE AI on October 1, 2026 at 22:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to stream-json v3.6.0 or later, which removes the quadratic comment scanning bug.
  • If upgrading cannot be performed immediately, limit the size of JSONC input by validating configuration size before parsing to mitigate excessive CPU usage.
  • Reconfigure or modify the application to use the plain JSON parser for configuration files, avoiding JSONC parsing entirely when possible, as it does not exhibit this issue.

Generated by OpenCVE AI on October 1, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Uhop
Uhop stream-json
Vendors & Products Uhop
Uhop stream-json

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0.
Title stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Uhop Stream-json
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T20:15:39.108Z

Reserved: 2026-10-01T18:54:15.118Z

Link: CVE-2026-104182

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T21:17:19.003

Modified: 2026-10-01T21:17:19.003

Link: CVE-2026-104182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:45:13Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity