PT-2026-28436 · Go+9 · Go+15
Published
2026-03-16
·
Updated
2026-05-21
·
CVE-2026-32285
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
versions prior to 2026
Description
The Delete function does not correctly validate offsets when processing malformed JSON input. This can result in a negative slice index and a runtime panic, potentially leading to a denial of service attack.
Recommendations
Ensure proper validation of offsets when processing JSON input for the Delete function.
Exploit
Fix
DoS
RCE
Out of bounds Read
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Go
Grafana Alloy
Red Hat Advanced Cluster Management For Kubernetes
Red Hat Openshift Container Platform
Red Hat Openshift Distributed Tracing
Red Hat Openstack Platform
Github.Com/Buger/Jsonparser
Golang-Github-Buger-Jsonparser
Govulncheck-Vulndb
Jsonparser
Mcphost
Prometheus
Rootio-Github.Com/Buger/Jsonparser
Tempo
Tempo-Fips
Terragrunt-Fips