Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32285

Опубликовано: 26 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

A flaw was found in github.com/buger/jsonparser. The Delete function, when processing malformed JSON input, fails to properly validate offsets. This vulnerability can lead to a negative slice index and a runtime panic, allowing a remote attacker to cause a denial of service (DoS) by providing specially crafted JSON data.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-operator-bundleWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-rhel9-operatorWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/lokistack-gateway-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/opa-openshift-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-rhel9-operatorNot affected
Red Hat Ansible Automation Platform 2ansible-automation-platform/platform-operator-bundleNot affected
Red Hat OpenShift Container Platform 4cri-toolsNot affected
Red Hat OpenShift Container Platform 4openshift4/container-networking-plugins-microshift-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/oc-mirror-plugin-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1285
https://bugzilla.redhat.com/show_bug.cgi?id=2451846github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input

EPSS

Процентиль: 52%
0.0075
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

CVSS3: 7.5
nvd
5 месяцев назад

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

CVSS3: 7.5
debian
5 месяцев назад

The Delete function fails to properly validate offsets when processing ...

CVSS3: 7.5
github
5 месяцев назад

github.com/buger/jsonparser has a denial of service vulnerability

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость функции Delete() языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 52%
0.0075
Низкий

7.5 High

CVSS3