EXECUTIVE SUMMARY:
Multiple vulnerabilities affecting stream-json versions affecting stream-json versions have been identified in stream-json: stream-json has a prototype pollution issue: Assembler writes this.current[this.key] on plain objects.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Multiple vulnerabilities affecting stream-json versions affecting stream-json versions have been identified in stream-json: stream-json has a prototype pollution issue: Assembler writes this.current[this.key] on plain objects.[emaillocker id="1283"]
CVE-2026-104183 (CVSS 5.1 — Medium): A prototype-pollution vulnerability in stream-json lets attacker-controlled JSON replace a parsed object's prototype.
CVE-2026-104182 (CVSS 6.2 — Medium): It is an algorithmic complexity vulnerability in stream-json where JSONC comments split across input chunks are repeatedly rescanned, causing O(n²) CPU consumption and potentially enabling denial-of-service conditions.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-mjw6-4jj6-33hc
https://github.com/advisories/GHSA-hqr4-qq8f-hg3x