Threat Advisory

stream-json Flaws Enable Prototype Alteration and Processing Loop Disruption

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting stream-json versions affecting stream-json versions have been identified in stream-json: stream-json has a prototype pollution issue: Assembler writes this.current[this.key] on plain objects.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting stream-json versions affecting stream-json versions have been identified in stream-json: stream-json has a prototype pollution issue: Assembler writes this.current[this.key] on plain objects.[emaillocker id="1283"]

CVE-2026-104183 (CVSS 5.1 — Medium): A prototype-pollution vulnerability in stream-json lets attacker-controlled JSON replace a parsed object's prototype.

CVE-2026-104182 (CVSS 6.2 — Medium): It is an algorithmic complexity vulnerability in stream-json where JSONC comments split across input chunks are repeatedly rescanned, causing O(n²) CPU consumption and potentially enabling denial-of-service conditions.

 

RECOMMENDATIONS:

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-mjw6-4jj6-33hc
https://github.com/advisories/GHSA-hqr4-qq8f-hg3x

[/emaillocker]
crossmenu