Repository navigation
chore(deps): update dependency smol-toml@<=1.7.0 to v1.9.0 [security] - #334
Conversation
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
View your CI Pipeline Execution ↗ for commit 47d32f4
☁️ Nx Cloud last updated this comment at |
commit: |
47d32f4 to
3d1d851
Compare
This PR contains the following updates:
1.7.1→1.9.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line
GHSA-r4xh-jqrq-34v2
More information
Details
Summary
parse()has a quadratic-time path inparseKey, reachable on default options with ordinary valid input. For every key line and table-header line,parseKey(dist/struct.js, lines 58 and 86) finds the dotted-key separator withctx.s.indexOf('.', ctx.p), wherectx.sis the whole document. When a key has no.ahead of it, that search runs all the way to the end of the input, and the result is then clamped back to the line terminatorendPtr- so everything scanned past the current line is wasted.parseKeyruns once per line, so a document of N dot-free keys costs O(n^2).The most ordinary TOML shape triggers it: a flat list of
key = valuelines, or a repeated[[a]]table. No dotted keys, no special options, valid input throughout.Proof of concept
Doubling the line count roughly quadruples the time:
Impact
Any service that runs
parse()on attacker-supplied TOML can be stalled. The work is synchronous, so it blocks the whole event loop, and the quadratic is unbounded: a ~7 MB body pins a core for about a minute, larger bodies for several.Patches
Version 1.9.0 uses a different implementation for parsing keys which is strictly linear.
Workarounds
Limit the maximum document size accepted when parsing arbitrary documents.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.