close
Skip to content

x/vulndb: potential Go vuln in github.com/buger/jsonparser: GHSA-6g7g-w4f8-9c9x #4739

Description

@GoVulnBot

Advisory GHSA-6g7g-w4f8-9c9x references a vulnerability in the following Go modules:

Module
github.com/buger/jsonparser

Description:
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/buger/jsonparser
      vulnerable_at: 1.1.1
summary: Denial of service in github.com/buger/jsonparser
ghsas:
    - GHSA-6g7g-w4f8-9c9x
references:
    - advisory: https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
    - report: https://github.com/buger/jsonparser/issues/275
    - report: https://github.com/golang/vulndb/issues/4514
    - web: https://cyber.securityinfinity.com/buger-jsonparser-negative-slice-panic-dos-2026
source:
    id: GHSA-6g7g-w4f8-9c9x
    created: 2026-03-18T13:01:54.616750494Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions