VYPR

swag

by Go Openapi

CVEs (1)

  • CVE-2026-93450HigSep 18, 2026
    risk 0.49cvss 7.5epss

    go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI…