id: GO-ID-PENDING
modules:
- module: github.com/buger/jsonparser
vulnerable_at: 1.1.1
summary: Denial of service in github.com/buger/jsonparser
ghsas:
- GHSA-6g7g-w4f8-9c9x
references:
- advisory: https://github.com/advisories/GHSA-6g7g-w4f8-9c9x
- report: https://github.com/buger/jsonparser/issues/275
- report: https://github.com/golang/vulndb/issues/4514
- web: https://cyber.securityinfinity.com/buger-jsonparser-negative-slice-panic-dos-2026
source:
id: GHSA-6g7g-w4f8-9c9x
created: 2026-03-18T13:01:54.616750494Z
review_status: UNREVIEWED
Advisory GHSA-6g7g-w4f8-9c9x references a vulnerability in the following Go modules:
Description:
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.