Comment Parsing Vulnerability in Stream-JSON Library by Uhop
CVE-2026-104182
What is CVE-2026-104182?
The Stream-JSON library, a lightweight tool for processing JSON and JSONC data, contains a vulnerability in its JSONC parser and verifier prior to version 3.6.0. This vulnerability arises from the library's handling of block and line comments, where the scan for comment terminators restarts unnecessarily from the opening slash when comments span across multiple input chunks. As a result, it can lead to excessive CPU usage, potentially stalling the Node.js event loop during processing of large valid comments. Although the impact is characterized as a local attack vector—since the JSONC input typically originates from user-controlled or locally owned configurations—the implications for performance degradation could affect application responsiveness significantly. This issue has been rectified in version 3.6.0.
Affected Version(s)
stream-json < 3.6.0
