CVE-2026-32285: Denial of service in github.com/buger/jsonparser
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
Security readout for executives and security teams
Plain-English summary
This flaw can let malformed JSON crash software that uses buger/jsonparser's Delete function. The business impact is availability: exposed services may stop handling requests if attacker-controlled JSON reaches the vulnerable path. The bundle does not show confirmed in-the-wild exploitation.
Executive priority
Prioritize remediation for internet-facing or high-availability services that process user-supplied JSON. The issue is not shown as actively exploited, but the unauthenticated network DoS profile warrants timely patch validation.
Technical view
The Delete function in github.com/buger/jsonparser fails to validate offsets for malformed JSON, leading to a negative slice index and Go runtime panic. CVSS 3.1 is 7.5, network-reachable, low complexity, unauthenticated, with high availability impact only.
Likely exposure
Exposure is most likely in Go services importing github.com/buger/jsonparser and calling Delete on JSON influenced by external users, APIs, queues, or files. The affected version data in the bundle is limited and should be verified against GO-2026-4514 and vendor advisories.
Exploitation context
The bundle includes a public research reference tagged exploit, but KEV is false and no cited source here confirms active exploitation. Treat this as a practical denial-of-service risk where malformed JSON can reach vulnerable parsing paths.
Researcher notes
Focus triage on reachability, not just dependency presence. The vulnerable condition is tied to Delete processing malformed JSON and producing a negative slice panic. Source evidence does not provide complete affected version or fixed-version details in the supplied bundle.
Mitigation direction
Inventory Go services using github.com/buger/jsonparser.
Identify code paths calling Delete on untrusted JSON.
Check GO-2026-4514 and upstream guidance for fixed versions.
Apply relevant vendor updates, including Red Hat errata where applicable.
Reject malformed JSON before affected Delete paths.
Use panic recovery to contain service impact.
Validation and detection
Search dependency manifests for github.com/buger/jsonparser.
Confirm whether Delete is reachable from external inputs.
Compare installed versions with GO-2026-4514 guidance.
Review Red Hat advisories for affected packaged components.
Test malformed JSON handling in a safe staging environment.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-125: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.