Intel

AIKIDO-2026-430108

smol-toml is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-r4xh-jqrq-34v2 Published 4 days ago

53

Medium Risk

This Affects:

JSsmol-toml
0.0.1 - 1.8.0
Fixed in 1.9.0
Are you affected? Scan for Free

TL;DR

parse() has a quadratic time path in parseKey, which on every key line and table header line scans from the current key position to the end of the whole document for the next dot. On an ordinary flat TOML document with many dot free key lines, or many repeated [[a]] tables, that scan repeats over the remaining document on each line, so parse time grows quadratically with document size on default options. Because parsing is synchronous, a multi megabyte externally supplied document can block the event loop for a minute or more. The fix replaces parseKey with a strictly linear implementation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

smol-toml is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 1.8.0.

How to fix this

Upgrade the smol-toml library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform