Junglewise Threat Intelligence

CVE-2026-63386: js-toml stack exhaustion in recursive parser

CVE-2026-63386 · Severity: medium · CVSS 5.3 · Published 2026-09-22

Technologies: Sunnyadn Js-Toml. Vendors: Sunnyadn.

Executive brief

js-toml is a JavaScript library for parsing TOML configuration files. A flaw in versions before 1.1.3 allows attacker-controlled input with deeply nested structures to crash the parser by exhausting the call stack, causing denial of service to applications that rely on it.

Technical details

The recursive parser and interpreter in js-toml do not bound nesting depth for arrays, inline tables, or dotted keys, allowing deeply nested or complex input to exhaust the V8 call stack and throw an uncaught RangeError instead of the documented SyntaxParseError. Applications that parse untrusted TOML and only catch SyntaxParseError will propagate the unexpected exception, terminating the process. Version 1.1.3 adds configurable recursion depth limits (default 100) and converts residual RangeErrors to SyntaxParseError.

Affected products

  • sunnyadn js-toml before 1.1.3

Timeline

  • 2026-09-22: disclosed
  • 2026-06-30: patched

References

Related threats