{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/smol-toml--1.7.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-85730"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["smol-toml (\u003c= 1.7.0)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe smol-toml library is susceptible to a denial-of-service (DoS) vulnerability, tracked as CVE-2026-85730. The vulnerability resides in the \u003ccode\u003eparse()\u003c/code\u003e function, which fails to correctly handle specific malformed TOML documents. When an array or inline table within a TOML document is followed by a comment that lacks a trailing newline at the end of the file, the parser's internal logic enters an infinite loop. During this loop, the parser incorrectly resets its cursor to the beginning of the input string, resulting in the thread pinning CPU usage at 100%. This vulnerability poses a significant risk to applications that parse arbitrary or untrusted TOML input, as a single malicious payload can effectively hang the application process. Defenders should prioritize updating the library to version 1.7.1 or later, where the parser logic has been corrected to exit the loop and return a proper \u003ccode\u003eTomlError\u003c/code\u003e.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eApplications that ingest and parse untrusted TOML input are highly vulnerable to service disruption. Successfully triggering this flaw causes immediate and persistent 100% CPU utilization, rendering the service unresponsive. This is particularly critical for web services or APIs that utilize \u003ccode\u003esmol-toml\u003c/code\u003e to process configuration files or user-provided data, potentially leading to widespread outages for dependent systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003esmol-toml\u003c/code\u003e to version 1.7.1 or later immediately to address CVE-2026-85730.\u003c/li\u003e\n\u003cli\u003eAudit application codebases to identify services that utilize \u003ccode\u003esmol-toml\u003c/code\u003e for parsing external, unvalidated TOML data.\u003c/li\u003e\n\u003cli\u003eImplement request timeout mechanisms and resource limits (CPU/memory) on processes responsible for parsing untrusted data to mitigate the impact of potential hanging conditions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T18:51:02Z","date_published":"2026-09-09T18:51:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-smol-toml-dos/","summary":"The smol-toml library (\u003c= 1.7.0) is vulnerable to a denial-of-service condition (CVE-2026-85730) where malformed TOML input triggers an infinite loop, causing 100% CPU utilization.","title":"Denial of Service in smol-toml via Malformed TOML","url":"https://feed.craftedsignal.io/briefs/2026-09-smol-toml-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Smol-Toml (\u003c= 1.7.0)","version":"https://jsonfeed.org/version/1.1"}