A AegiFlow
HIGHCVSS 8.2EPSS 0.4%

CVE-2026-85730

CVE-2026-85730 updated by NVD

Published
2026-09-09
Modified
2026-09-11
EPSS percentile
32%
Sources
github-advisory, nvd

Summary

smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is followed by a comment with no trailing newline. In src/util.ts, skipUntil() calls indexOfNewline(), receives -1 at the end of input, and resets the cursor to the beginning of the string instead of leaving the structure scan. The parser then hangs indefinitely and can consume a service's processing capacity when an application parses attacker-controlled TOML. This issue is fixed in version 1.7.1.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmsmol-toml1.7.1

Remediation: Upgrade to 1.7.1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.