go-openapi/swag 的 jsonutils 组件在 0.27.1 之前版本中存在堆栈溢出漏洞,该漏洞源于在解析和序列化有序 JSON 时存在无深度限制的无限递归。远程未认证的攻击者可以通过向接受 OpenAPI 规范的 API 提交深度嵌套的 JSON 文档,触发致命的堆栈溢出,从而导致进程终止,并使所有正在处理中的请求失败。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| go-openapi | swag | < 0.27.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| go-openapi | swag | 0 ~ 0.27.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet