Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
toml-node: Uncontrolled Recursion
Vulnerability Description
toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions recurse through nested arrays and inline tables without a depth limit. A remote unauthenticated application parsing an attacker-controlled TOML document containing a few thousand nested arrays or inline tables can exhaust the Node.js call stack, raise an unexpected RangeError rather than the parser's SyntaxError, and terminate an unprotected request worker or process. The corresponding grammar source is src/toml.pegjs, where the generated parser must be bounded. This issue is fixed in version 4.2.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未经控制的递归
Vulnerability Title
Michelle Tilley TOML Parser for Node.js 资源管理错误漏洞
Vulnerability Description
Michelle Tilley TOML Parser for Node.js是Michelle Tilley个人开发者的一款TOML格式解析器。 Michelle Tilley TOML Parser for Node.js 4.2.0之前版本存在资源管理错误漏洞,该漏洞源于解析器在解析嵌套数组和内联表时未设置深度限制,可能耗尽Node.js调用栈并导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A