Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 04 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is followed by a comment with no trailing newline. In src/util.ts, skipUntil() calls indexOfNewline(), receives -1 at the end of input, and resets the cursor to the beginning of the string instead of leaving the structure scan. The parser then hangs indefinitely and can consume a service's processing capacity when an application parses attacker-controlled TOML. This issue is fixed in version 1.7.1. | |
| Title | smol-toml: Denial of Service via malformed TOML documents | |
| Weaknesses | CWE-606 CWE-835 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-04T17:40:50.595Z
Reserved: 2026-09-04T14:45:10.649Z
Link: CVE-2026-85730
Updated: 2026-09-04T17:40:45.655Z
Status : Received
Published: 2026-09-04T16:18:23.417
Modified: 2026-09-04T18:18:07.040
Link: CVE-2026-85730
No data.
OpenCVE Enrichment
Updated: 2026-09-04T18:30:04Z