Skip to content

chore(deps): update dependency smol-toml@<=1.7.0 to v1.9.0 [security] - #334

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/npm-smol-toml-=1.7.0-vulnerability
Oct 7, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/npm-smol-toml-=1.7.0-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
smol-toml@<=1.7.0 1.7.1 → 1.9.0 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line

GHSA-r4xh-jqrq-34v2

More information

Details

Summary

parse() has a quadratic-time path in parseKey, reachable on default options with ordinary valid input. For every key line and table-header line, parseKey (dist/struct.js, lines 58 and 86) finds the dotted-key separator with ctx.s.indexOf('.', ctx.p), where ctx.s is the whole document. When a key has no . ahead of it, that search runs all the way to the end of the input, and the result is then clamped back to the line terminator endPtr - so everything scanned past the current line is wasted. parseKey runs once per line, so a document of N dot-free keys costs O(n^2).

The most ordinary TOML shape triggers it: a flat list of key = value lines, or a repeated [[a]] table. No dotted keys, no special options, valid input throughout.

Proof of concept
import { parse } from 'smol-toml'

let doc = ''
for (let i = 0; i < 256000; i++) doc += 'k' + i + ' = 1\n'

console.time('parse')
parse(doc) // ~2.8 MB of valid TOML, default options
console.timeEnd('parse')

Doubling the line count roughly quadruples the time:

lines size parse()
32k 0.3 MB 0.3 s
64k 0.7 MB 1.0 s
128k 1.4 MB 3.5 s
256k 2.8 MB 14 s
Impact

Any service that runs parse() on attacker-supplied TOML can be stalled. The work is synchronous, so it blocks the whole event loop, and the quadratic is unbounded: a ~7 MB body pins a core for about a minute, larger bodies for several.

Patches

Version 1.9.0 uses a different implementation for parsing keys which is strictly linear.

Workarounds

Limit the maximum document size accepted when parsing arbitrary documents.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Oct 7, 2026
@changeset-bot

changeset-bot Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 3d1d851

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 440ac47a-35d9-44e3-bfb4-a517619dc466

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@nx-cloud

nx-cloud Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

View your CI Pipeline Execution ↗ for commit 47d32f4

Command Status Duration Result
nx run-many --targets=build ✅ Succeeded <1s View ↗
nx affected --targets=test:eslint,test:sherif,t... ✅ Succeeded 1m 7s View ↗

☁️ Nx Cloud last updated this comment at 2026-10-07 15:53:32 UTC

@pkg-pr-new

pkg-pr-new Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@tanstack/intent@334

commit: 3d1d851

@codspeed

codspeed Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 12 untouched benchmarks


Comparing renovate/npm-smol-toml-=1.7.0-vulnerability (3d1d851) with main (c53aa59)

Open in CodSpeed

@renovate
renovate Bot force-pushed the renovate/npm-smol-toml-=1.7.0-vulnerability branch from 47d32f4 to 3d1d851 Compare October 7, 2026 15:51
@renovate
renovate Bot merged commit ab9877c into main Oct 7, 2026
10 checks passed
@renovate
renovate Bot deleted the renovate/npm-smol-toml-=1.7.0-vulnerability branch October 7, 2026 21:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants