{"id":"GHSA-r4xh-jqrq-34v2","summary":"smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line","details":"### Summary\n\n`parse()` has a quadratic-time path in `parseKey`, reachable on default options with ordinary valid input. For every key line and table-header line, `parseKey` (dist/struct.js, lines 58 and 86) finds the dotted-key separator with `ctx.s.indexOf('.', ctx.p)`, where `ctx.s` is the whole document. When a key has no `.` ahead of it, that search runs all the way to the end of the input, and the result is then clamped back to the line terminator `endPtr` - so everything scanned past the current line is wasted. `parseKey` runs once per line, so a document of N dot-free keys costs O(n^2).\n\nThe most ordinary TOML shape triggers it: a flat list of `key = value` lines, or a repeated `[[a]]` table. No dotted keys, no special options, valid input throughout.\n\n### Proof of concept\n\n```js\nimport { parse } from 'smol-toml'\n\nlet doc = ''\nfor (let i = 0; i \u003c 256000; i++) doc += 'k' + i + ' = 1\\n'\n\nconsole.time('parse')\nparse(doc) // ~2.8 MB of valid TOML, default options\nconsole.timeEnd('parse')\n```\n\nDoubling the line count roughly quadruples the time:\n\n| lines | size | parse() |\n|---|---|---|\n| 32k | 0.3 MB | 0.3 s |\n| 64k | 0.7 MB | 1.0 s |\n| 128k | 1.4 MB | 3.5 s |\n| 256k | 2.8 MB | 14 s |\n\n### Impact\nAny service that runs `parse()` on attacker-supplied TOML can be stalled. The work is synchronous, so it blocks the whole event loop, and the quadratic is unbounded: a ~7 MB body pins a core for about a minute, larger bodies for several.\n\n### Patches\nVersion 1.9.0 uses a different implementation for parsing keys which is strictly linear.\n\n### Workarounds\nLimit the maximum document size accepted when parsing arbitrary documents.","modified":"2026-10-06T00:00:11.869852163Z","published":"2026-10-05T23:41:14Z","database_specific":{"cwe_ids":["CWE-407"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-05T23:41:14Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/squirrelchat/smol-toml/security/advisories/GHSA-r4xh-jqrq-34v2"},{"type":"WEB","url":"https://github.com/squirrelchat/smol-toml/commit/99102aa57fc932f760ea9c15b4cf1c181f952d24"},{"type":"PACKAGE","url":"https://github.com/squirrelchat/smol-toml"},{"type":"WEB","url":"https://github.com/squirrelchat/smol-toml/releases/tag/v1.9.0"}],"affected":[{"package":{"name":"smol-toml","ecosystem":"npm","purl":"pkg:npm/smol-toml"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.9.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.8.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-r4xh-jqrq-34v2/GHSA-r4xh-jqrq-34v2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}