Stack Overflow Vulnerability in go-openapi/swag JSON Utilities
CVE-2026-93450

8.7HIGH

Key Information:

Vendor

Go-openapi

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-93450?

The go-openapi/swag JSON utilities prior to version 0.27.1 are susceptible to a stack overflow due to unbounded recursion during the parsing and serialization of ordered JSON. This flaw allows remote unauthenticated attackers to submit highly nested JSON documents to systems utilizing OpenAPI specifications, leading to fatal stack overflow errors that can crash the process, disrupting all ongoing requests. This vulnerability poses significant risks for software relying on JSON data structures, necessitating prompt attention and remediation.

Affected Version(s)

swag 0 < 0.27.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wei Zhang, PayPal Cyber Security Team
.