Denial of Service Vulnerability in Golang's JSON Parser
CVE-2026-32285
7.5HIGH
What is CVE-2026-32285?
The JSON Parser in Golang is susceptible to a denial of service attack due to inadequate validation of offsets during the processing of malformed JSON input. When the Delete function is called with such input, it may result in a negative slice index, leading to a runtime panic. This vulnerability can compromise application stability and availability, making it a critical concern for developers utilizing Golang's JSON handling capabilities.
Affected Version(s)
github.com/buger/jsonparser 0 < 1.1.2
