Impact
The vulnerability in the stream-json library causes the JSONC parser and verifier to repeatedly scan the full accumulated comment whenever a block or line comment spans an input chunk. This causes quadratic CPU consumption and can stall the Node.js event loop, effectively denying service to the application. The weakness falls under CWE‑407: Incorrect Resource Exhaustion Evaluation.
Affected Systems
The affected product is uhop's stream-json. Versions prior to 3.6.0 are vulnerable; the fix is included in release 3.6.0 and later.
Risk and Exploitability
The CVSS score of 6.2 reflects a moderate severity. Exploit likelihood is not quantified due to unavailable EPSS data, and the vulnerability is not listed in the CISA KEV catalog. The documented attack vector is local, meaning that an attacker would need to supply JSONC input from a locally controlled or user‑managed configuration. No known public exploits are reported as of this analysis.
OpenCVE Enrichment