SCA: security update for stream-json (GHSA-hqr4-qq8f-hg3x)

medium Tenable Self-Hosted Container Security Plugin ID 472985

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory
footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-
json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line
comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid
comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop.
The maintainer characterizes the attack vector as local because the documented JSONC input is locally
owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only
scope does not include the plain JSON parser, which advances through and discards consumed string and
number data. This issue is fixed in version 3.6.0. (CVE-2026-104182)

Solution

Update the stream-json library and its related packages to version 3.6.0 or later.

See Also

https://github.com/advisories/GHSA-hqr4-qq8f-hg3x

Plugin Details

Severity: Medium

ID: 472985

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/6/2026

Updated: 10/6/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.64

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-104182

CVSS v3

Risk Factor: Medium

Base Score: 6.2

Temporal Score: 5.4

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/5/2026

Vulnerability Publication Date: 10/1/2026

Reference Information

CVE: CVE-2026-104182

cwe: CWE-407