stream-json 是一个用于处理 JSON 和 JSONC 的流组件微型库,具有极小的内存占用。在 3.6.0 版本之前,位于 的 JSONC 解析器和 中的验证器,在块注释或行注释跨越多个输入数据块时,会从起始斜杠处重新开始扫描注释终止符,同时保留已累积的注释缓冲区。因此,将一个大型有效注释拆分为许多小块进行传输会导致 CPU 执行呈二次方增长的计算量,从而可能阻塞 Node.js 事件循环。维护者将该攻击向量归类为本地型,因为文档中所述的 JSONC 输入通常是本地拥有或用户可控的配置数据,而非面向公开互
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| uhop | stream-json | < 3.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| uhop | stream-json | < 3.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet