Comment Parsing Vulnerability in Stream-JSON Library by Uhop
CVE-2026-104182

6.2MEDIUM

Key Information:

Vendor

Uhop

Vendor
CVE Published:
1 October 2026

What is CVE-2026-104182?

The Stream-JSON library, a lightweight tool for processing JSON and JSONC data, contains a vulnerability in its JSONC parser and verifier prior to version 3.6.0. This vulnerability arises from the library's handling of block and line comments, where the scan for comment terminators restarts unnecessarily from the opening slash when comments span across multiple input chunks. As a result, it can lead to excessive CPU usage, potentially stalling the Node.js event loop during processing of large valid comments. Although the impact is characterized as a local attack vector—since the JSONC input typically originates from user-controlled or locally owned configurations—the implications for performance degradation could affect application responsiveness significantly. This issue has been rectified in version 3.6.0.

Affected Version(s)

stream-json < 3.6.0

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.