PT-2026-96973 · Npm · Js-Toml
CVE-2026-63386
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
js-toml versions prior to 1.1.3
Description
The
load() function fails to limit nesting or dotted-key depth within the recursive parser at src/load/parser.ts and the interpreter at src/load/interpreter.ts. Consequently, processing deeply nested arrays, deeply nested inline tables, or long dotted keys can exhaust the V8 call stack, triggering a raw RangeError instead of the expected SyntaxParseError. If an application parses attacker-controlled TOML and only handles SyntaxParseError, the unexpected exception can cause a worker or process to terminate, leading to a denial of service. This synchronous exception can be caught by consumers handling all exceptions and does not impact confidentiality or integrity.Recommendations
Update to version 1.1.3.
Exploit
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Js-Toml