CVE-2026-104182
Received Received - Intake

Denial of Service in stream-json JSONC Parser

Vulnerability report for CVE-2026-104182, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
stream-json stream-json 3.6.0
stream-json stream-json to 3.6.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the stream-json library, specifically in its JSONC parser and verifier. When processing large comments split across many small chunks, the parser restarts comment scanning from the start repeatedly, causing excessive CPU usage and potentially stalling the Node.js event loop. It is fixed in version 3.6.0.

Detection Guidance

This vulnerability is specific to the stream-json library's JSONC parser and verifier. Detection requires checking if your system uses a version of stream-json prior to 3.6.0. Run: npm list stream-json to check the installed version. If the version is below 3.6.0, the system is vulnerable.

Impact Analysis

If you use the affected stream-json library with JSONC input, an attacker could exploit this to cause high CPU usage, leading to performance degradation or a denial of service by stalling the event loop in Node.js applications.

Mitigation Strategies

Upgrade stream-json to version 3.6.0 or later immediately. Use: npm update stream-json or npm install stream-json@latest. If upgrading is not possible, consider disabling JSONC parsing in affected applications or restricting input sources to trusted origins.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104182. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart