GHSA-r4xh-jqrq-34v2: Medium severity npm/smol-toml vulnerability

Published Oct 5, 2026
·
Updated

Summary

parse() has a quadratic-time path in parseKey, reachable on default options with ordinary valid input. For every key line and table-header line, parseKey (dist/struct.js, lines 58 and 86) finds the dotted-key separator with ctx.s.indexOf('.', ctx.p), where ctx.s is the whole document. When a key has no . ahead of it, that search runs all the way to the end of the input, and the result is then clamped back to the line terminator endPtr - so everything scanned past the current line is wasted. parseKey runs once per line, so a document of N dot-free keys costs O(n^2).

The most ordinary TOML shape triggers it: a flat list of key = value lines, or a repeated [[a]] table. No dotted keys, no special options, valid input throughout.

Proof of concept

js import { parse } from 'smol-toml'

let doc = '' for (let i = 0; i < 256000; i++) doc += 'k' + i + ' = 1\n'

console.time('parse') parse(doc) // ~2.8 MB of valid TOML, default options console.timeEnd('parse')

Doubling the line count roughly quadruples the time:

| lines | size | parse() | |---|---|---| | 32k | 0.3 MB | 0.3 s | | 64k | 0.7 MB | 1.0 s | | 128k | 1.4 MB | 3.5 s | | 256k | 2.8 MB | 14 s |

Impact Any service that runs parse() on attacker-supplied TOML can be stalled. The work is synchronous, so it blocks the whole event loop, and the quadratic is unbounded: a ~7 MB body pins a core for about a minute, larger bodies for several.

Patches Version 1.9.0 uses a different implementation for parsing keys which is strictly linear.

Workarounds Limit the maximum document size accepted when parsing arbitrary documents.

Affected Software

1 affected componentFixes available
npm/smol-toml<=1.8.0
1.9.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/smol-toml to a version that resolves this vulnerability.

    Fixed in 1.9.0
  2. Upgrade

    Upgrade smol-toml to a version that resolves this vulnerability.

    Fixed in 1.9.0
  3. Compensating control

    Limit the maximum document size accepted when parsing attacker-supplied or arbitrary TOML documents.

Event History

Oct 5, 2026
Advisory Published
via GitHub·11:41 PM
Data Sourced
via GitHub·11:41 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What inputs are most likely to trigger the performance issue?

Valid TOML documents containing many dot-free key/value lines, such as a flat sequence of "key = value" entries, trigger the quadratic path. Repeated [[a]] table headers can also trigger it; dotted keys are not required.

2

Is a non-default configuration or malformed input required?

No. The issue is reachable with default parse() options and ordinary valid TOML input, without special configuration or invalid syntax.

3

What is the practical impact of supplying a large triggering document?

Parsing time grows quadratically with the number of affected lines, so doubling the line count roughly quadruples parsing time. In the provided example, a 2.8 MB document with 256,000 key/value lines took about 14 seconds to parse.

4

How can I determine whether my application is exposed?

An application is exposed if it uses smol-toml's parse() on TOML content that an attacker can make large or control, particularly flat documents with many keys or repeated table headers. The affected behavior occurs during parsing, before any application-specific interpretation of the parsed values.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203