Uncontrolled Recursion Affecting github.com/go-openapi/swag/jsonutils/adapters/easyjson/json package, versions <0.27.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.66% (51st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMGOOPENAPISWAGJSONUTILSADAPTERSEASYJSONJSON-19963956
  • published20 Sept 2026
  • disclosed18 Sept 2026
  • creditweiz-cn

Introduced: 18 Sep 2026

NewCVE-2026-93450  (opens in a new tab)
CWE-674  (opens in a new tab)

How to fix?

Upgrade github.com/go-openapi/swag/jsonutils/adapters/easyjson/json to version 0.27.1 or higher.

Overview

Affected versions of this package are vulnerable to Uncontrolled Recursion in the ordered-JSON marshal/unmarshal paths through the jsonutils/adapters/stdlib/json and jsonutils/adapters/easyjson/json ordered map handlers. An attacker can crash the process by sending a deeply nested JSON document to ReadJSON/JSONMapSlice.UnmarshalJSON or by causing WriteJSON/JSONMapSlice.MarshalJSON to process an equally deep in-memory JSONMapSlice. The unbounded recursion exhausts the goroutine stack and triggers a non-recoverable fatal error: stack overflow, terminating the serving process and dropping in-flight requests.

CVSS Base Scores

version 4.0
version 3.1