smol-toml is vulnerable to Denial of Service (DoS)
53
Medium Risk
parse() has a quadratic time path in parseKey, which on every key line and table header line scans from the current key position to the end of the whole document for the next dot. On an ordinary flat TOML document with many dot free key lines, or many repeated [[a]] tables, that scan repeats over the remaining document on each line, so parse time grows quadratically with document size on default options. Because parsing is synchronous, a multi megabyte externally supplied document can block the event loop for a minute or more. The fix replaces parseKey with a strictly linear implementation.
You are affected if you are using a version that falls within the vulnerable range.
smol-toml is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 1.8.0.
Upgrade the smol-toml library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.