High severity7.5NVD Advisory· Published Sep 18, 2026
CVE-2026-93450
CVE-2026-93450
Description
go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI specifications, causing fatal stack overflow that terminates the process and all in-flight requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <0.27.1
Patches
Vulnerability mechanics
References
5- github.com/go-openapi/swag/blob/v0.27.0/jsonutils/adapters/stdlib/json/adapter.gonvd
- github.com/go-openapi/swag/blob/v0.27.0/jsonutils/adapters/stdlib/json/ordered_map.gonvd
- github.com/go-openapi/swag/commit/0c24346ced59a25811e8694a915e7131d25ccb0envd
- github.com/go-openapi/swag/security/advisories/GHSA-xh24-9qpg-8w28nvd
- www.vulncheck.com/advisories/go-openapi-swag-jsonutils-before-0.27.1-uncontrolled-recursion-in-ordered-json-marshal-and-unmarshalnvd
News mentions
0No linked articles in our index yet.