GHSA-r4xh-jqrq-34v2Medium· 5.3▾ Sunlitsmol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
parse() has a quadratic-time path in parseKey, reachable on default options with ordinary valid input. For every key line and table-header line, parseKey (dist/struct.js, lines 58 and 86) finds the dotted-key separator with ctx.s.indexOf('.', ctx.p), where ctx.s is the whole document. When a key has no . ahead of it, that search runs all the way to the end of the input, and the result is then clamped back to the line terminator endPtr - so everything scanned past the current line is wasted. parseKey runs once per line, so a document of N dot-free keys costs O(n^2).
The most ordinary TOML shape triggers it: a flat list of key = value lines, or a repeated [[a]] table. No dotted keys, no special options, valid input throughout.
import { parse } from 'smol-toml'
let doc = ''
for (let i = 0; i < 256000; i++) doc += 'k' + i + ' = 1\n'
console.time('parse')
parse(doc) // ~2.8 MB of valid TOML, default options
console.timeEnd('parse')
Doubling the line count roughly quadruples the time:
| lines | size | parse() |
|---|---|---|
| 32k | 0.3 MB | 0.3 s |
| 64k | 0.7 MB | 1.0 s |
| 128k | 1.4 MB | 3.5 s |
| 256k | 2.8 MB | 14 s |
Any service that runs parse() on attacker-supplied TOML can be stalled. The work is synchronous, so it blocks the whole event loop, and the quadratic is unbounded: a ~7 MB body pins a core for about a minute, larger bodies for several.
Version 1.9.0 uses a different implementation for parsing keys which is strictly linear.
Limit the maximum document size accepted when parsing arbitrary documents.
smol-toml <= 1.8.0Upgrade to a patched release:
smol-toml 1.9.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85730High· 8.2smol-toml is a small, fast, and correct TOML parser and serializer
CVE-2024-23684High· 7.5Inefficient algorithmic complexity in DecodeFromBytes function in com.upokecenter.cbor Java implementation of Concise Binary Object Representation (CBOR) versions 4.0.0 to 4.5.1 allows an attacker to cause a denial of service by passing …
CVE-2024-21909High· 7.5PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability
GHSA-vm5r-23w9-m8hxHigh· 7.5Duplicate Advisory: Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
CVE-2026-104844Medium· 5.9PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it
CVE-2026-104182Medium· 6.2stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint