๐Ÿ” CVE Alert

CVE-2026-104182

MEDIUM 6.2

stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk

CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th

stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0.

CWE CWE-407
Vendor uhop
Product stream-json
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for uhop stream-json

Be the first to know when new medium vulnerabilities affecting uhop stream-json are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

uhop / stream-json
< 3.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/uhop/stream-json/security/advisories/GHSA-hqr4-qq8f-hg3x github.com: https://github.com/uhop/stream-json/commit/c0299dc168ce9455ef5ca5b6a0f6850ee7fa0468 github.com: https://github.com/uhop/stream-json/releases/tag/3.6.0