High severityNVD Advisory· Published Oct 22, 2021· Updated Aug 4, 2024
CVE-2021-42836
CVE-2021-42836
Description
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/tidwall/gjsonGo | < 1.9.3 | 1.9.3 |
Affected products
2- GJSON/GJSONdescription
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-ppj4-34rq-v8j9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-42836ghsaADVISORY
- github.com/tidwall/gjson/commit/590010fdac311cc8990ef5c97448d4fec8f29944ghsax_refsource_MISCWEB
- github.com/tidwall/gjson/commit/77a57fda87dca6d0d7d4627d512a630f89a91c96ghsax_refsource_MISCWEB
- github.com/tidwall/gjson/compare/v1.9.2...v1.9.3ghsax_refsource_MISCWEB
- github.com/tidwall/gjson/issues/236ghsax_refsource_MISCWEB
- github.com/tidwall/gjson/issues/237ghsax_refsource_MISCWEB
- pkg.go.dev/vuln/GO-2021-0265ghsaWEB
News mentions
0No linked articles in our index yet.