CVE-2026-85730: smol-toml: Denial of Service via malformed TOML documents
smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is followed by a comment with no trailing newline. In src/util.ts, skipUntil() calls indexOfNewline(), receives -1 at the end of input, and resets the cursor to the beginning of the string instead of leaving the structure scan. The parser then hangs indefinitely and can consume a service's processing capacity when an application parses attacker-controlled TOML. This issue is fixed in version 1.7.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
smol-tomlto a version that resolves this vulnerability.Fixed in 1.7.1
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service condition?
Applications using smol-toml versions prior to 1.7.1 are exposed when they parse attacker-controlled TOML input. A crafted document can cause parsing to hang and consume processing capacity.
What input is required to trigger the issue?
The TOML must contain a value inside an array or inline table followed by a comment that has no trailing newline at the end of the input.
What is the remediation?
Upgrade smol-toml to version 1.7.1, which fixes the parser behavior.