CVE-2026-85730, with a CVSS score of 8.2, is a high-severity vulnerability affecting smol-toml versions less than or equal to 1.7.0 that causes denial-of-service via malformed TOML documents, allowing an attacker to force the parser into an infinite loop when a value inside an array or inline table is followed by a comment without trailing newline, compromising service availability; applications parsing arbitrary TOML documents can suffer major availability issues if they receive malicious input, with severe impact for use-cases involving untrusted sources. This flaw type is a CWE-606 and CWE-835 issue, which involves the improper handling of comments in structured data, leading to an infinite loop that consumes CPU resources and prevents the parser from exiting. The attack vector is network-based (AV:N), as it can be exploited by sending malicious TOML documents to the application, making it vulnerable to denial-of-service attacks. The business impact is significant, as applications relying on smol-toml for parsing arbitrary TOML documents may experience major availability issues and service downtime if they receive malicious input.
We recommend you to update smol-toml to version 1.7.1.[/subscribe_to_unlock_form]
CVE-2026-85730, with a CVSS score of 8.2, is a high-severity vulnerability affecting smol-toml versions less than or equal to 1.7.0 that causes denial-of-service via malformed TOML documents, allowing an attacker to force the parser into an infinite loop when a value inside an array or inline table is followed by a comment without trailing newline, compromising service availability; applications parsing arbitrary TOML documents can suffer major availability issues if they receive malicious input, with severe impact for use-cases involving untrusted sources. This flaw type is a CWE-606 and CWE-835 issue, which involves the improper handling of comments in structured data, leading to an infinite loop that consumes CPU resources and prevents the parser from exiting. The attack vector is network-based (AV:N), as it can be exploited by sending malicious TOML documents to the application, making it vulnerable to denial-of-service attacks. The business impact is significant, as applications relying on smol-toml for parsing arbitrary TOML documents may experience major availability issues and service downtime if they receive malicious input.
We recommend you to update smol-toml to version 1.7.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]