{"id":"GHSA-r4xh-jqrq-34v2","title":"smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line","summary":"smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line","severity":"medium","cvss":5.3,"cwe":["CWE-407"],"vendor":"smol-toml","product":"smol-toml","ecosystem":"npm","affected":["smol-toml <= 1.8.0"],"patched":["smol-toml 1.9.0"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T23:41:15Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-r4xh-jqrq-34v2","references":[{"url":"https://github.com/squirrelchat/smol-toml/security/advisories/GHSA-r4xh-jqrq-34v2"},{"url":"https://github.com/squirrelchat/smol-toml/commit/99102aa57fc932f760ea9c15b4cf1c181f952d24"},{"url":"https://github.com/squirrelchat/smol-toml/releases/tag/v1.9.0"},{"url":"https://github.com/advisories/GHSA-r4xh-jqrq-34v2"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-06T00:37:36.241Z","slug":"GHSA-r4xh-jqrq-34v2","body":"## Overview\n\n### Summary\n\n`parse()` has a quadratic-time path in `parseKey`, reachable on default options with ordinary valid input. For every key line and table-header line, `parseKey` (dist/struct.js, lines 58 and 86) finds the dotted-key separator with `ctx.s.indexOf('.', ctx.p)`, where `ctx.s` is the whole document. When a key has no `.` ahead of it, that search runs all the way to the end of the input, and the result is then clamped back to the line terminator `endPtr` - so everything scanned past the current line is wasted. `parseKey` runs once per line, so a document of N dot-free keys costs O(n^2).\n\nThe most ordinary TOML shape triggers it: a flat list of `key = value` lines, or a repeated `[[a]]` table. No dotted keys, no special options, valid input throughout.\n\n### Proof of concept\n\n```js\nimport { parse } from 'smol-toml'\n\nlet doc = ''\nfor (let i = 0; i < 256000; i++) doc += 'k' + i + ' = 1\\n'\n\nconsole.time('parse')\nparse(doc) // ~2.8 MB of valid TOML, default options\nconsole.timeEnd('parse')\n```\n\nDoubling the line count roughly quadruples the time:\n\n| lines | size | parse() |\n|---|---|---|\n| 32k | 0.3 MB | 0.3 s |\n| 64k | 0.7 MB | 1.0 s |\n| 128k | 1.4 MB | 3.5 s |\n| 256k | 2.8 MB | 14 s |\n\n### Impact\nAny service that runs `parse()` on attacker-supplied TOML can be stalled. The work is synchronous, so it blocks the whole event loop, and the quadratic is unbounded: a ~7 MB body pins a core for about a minute, larger bodies for several.\n\n### Patches\nVersion 1.9.0 uses a different implementation for parsing keys which is strictly linear.\n\n### Workarounds\nLimit the maximum document size accepted when parsing arbitrary documents.\n\n## Affected packages\n\n- `smol-toml <= 1.8.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `smol-toml 1.9.0`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}