<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 05:40:18 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-380898</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-380898</link>
      <description>EUVD-2026-380898</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-380898</guid>
    </item>
    <item>
      <title>fkie_cve-2026-104182</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-104182</link>
      <description>&lt;p&gt;stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-104182</guid>
    </item>
    <item>
      <title>GHSA-hqr4-qq8f-hg3x — stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hqr4-qq8f-hg3x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: stream-json&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The JSONC parser (`stream-json/jsonc/parser.js`) and verifier (`stream-json/jsonc/verifier.js`) scan a comment for its terminator starting from the comment&amp;#39;s opening `/` on every input chunk. When a comment doesn&amp;#39;t finish inside the current buffer, the scanner returns the comment&amp;#39;s start offset and the buffer keeps the whole comment, so the next chunk re-scans everything seen so far. A single comment of length n delivered across many chunks costs O(n²) CPU.&lt;/p&gt;
&lt;p&gt;This is the same class as GHSA-528h-pc64-c93x (path filters, medium, CWE-407): an algorithmic-complexity re-scan in a streaming feature. It&amp;#39;s a different code path though — the comment scanner in `handleComment`, which the 3.5.0 depth cap doesn&amp;#39;t touch — so upgrading past that advisory doesn&amp;#39;t help here. The plain JSON parser is fine: its strings and numbers advance and drop consumed bytes, and only comments retain and re-scan.&lt;/p&gt;
&lt;p&gt;## Proof of concept&lt;/p&gt;
&lt;p&gt;```
npm i stream-json@3.5.0
```&lt;/p&gt;
&lt;p&gt;```js
import Parser from &amp;#39;stream-json/jsonc/parser.js&amp;#39;;&lt;/p&gt;
&lt;p&gt;function feed(N) {
  return new Promise(resolve =&amp;gt; {
    const stream = Parser.asStream();            // default options
    stream.on(&amp;#39;data&amp;#39;, () =&amp;gt; {});
    stream.on(&amp;#39;error&amp;#39;, () =&amp;gt; {});
    stream.on(&amp;#39;end&amp;#39;, resolve);
    const doc = &amp;#39;/*&amp;#39; + &amp;#39;a&amp;#39;.repeat(N) + &amp;#39;*/1&amp;#39;;     // one valid, closed comment
    for (let i = 0; i &amp;lt; doc.length; i += 16384)   // 16 KB pieces, as a socket delivers a body
      stream.write(doc.slice(i, i + 16384));
    stream.end();
  });
}
```&lt;/p&gt;
&lt;p&gt;Timing the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: stream-json&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The JSONC parser (`stream-json/jsonc/parser.js`) and verifier (`stream-json/jsonc/verifier.js`) scan a comment for its terminator starting from the comment&amp;#39;s opening `/` on every input chunk. When a comment doesn&amp;#39;t finish inside the current buffer, the scanner returns the comment&amp;#39;s start offset and the buffer keeps the whole comment, so the next chunk re-scans everything seen so far. A single comment of length n delivered across many chunks costs O(n²) CPU.&lt;/p&gt;
&lt;p&gt;This is the same class as GHSA-528h-pc64-c93x (path filters, medium, CWE-407): an algorithmic-complexity re-scan in a streaming feature. It&amp;#39;s a different code path though — the comment scanner in `handleComment`, which the 3.5.0 depth cap doesn&amp;#39;t touch — so upgrading past that advisory doesn&amp;#39;t help here. The plain JSON parser is fine: its strings and numbers advance and drop consumed bytes, and only comments retain and re-scan.&lt;/p&gt;
&lt;p&gt;## Proof of concept&lt;/p&gt;
&lt;p&gt;```
npm i stream-json@3.5.0
```&lt;/p&gt;
&lt;p&gt;```js
import Parser from &amp;#39;stream-json/jsonc/parser.js&amp;#39;;&lt;/p&gt;
&lt;p&gt;function feed(N) {
  return new Promise(resolve =&amp;gt; {
    const stream = Parser.asStream();            // default options
    stream.on(&amp;#39;data&amp;#39;, () =&amp;gt; {});
    stream.on(&amp;#39;error&amp;#39;, () =&amp;gt; {});
    stream.on(&amp;#39;end&amp;#39;, resolve);
    const doc = &amp;#39;/*&amp;#39; + &amp;#39;a&amp;#39;.repeat(N) + &amp;#39;*/1&amp;#39;;     // one valid, closed comment
    for (let i = 0; i &amp;lt; doc.length; i += 16384)   // 16 KB pieces, as a socket delivers a body
      stream.write(doc.slice(i, i + 16384));
    stream.end();
  });
}
```&lt;/p&gt;
&lt;p&gt;Timing the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hqr4-qq8f-hg3x</guid>
    </item>
  </channel>
</rss>
