AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-104182.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 6.2CVSS 3.1 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSDeferredModified Oct 05, 2026

Disclosure summary

stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0.

Source-reported weakness categories

CWE-407

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-hqr4-qq8f-hg3x

Open original source · Updated Oct 05, 2026

stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
npmstream-json3.6.0
NIST National Vulnerability Database · NVD-CVE-2026-104182

Open original source · Updated Oct 05, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

Original records & references

PUBLISHED 2026-10-01T17:17:19-04:00
MODIFIED 2026-10-05T17:16:32-04:00
INGESTED 2026-10-06T11:45:14-04:00