PatchSiren cyber security CVE debrief
CVE-2026-32285 github.com/buger/jsonparser CVE debrief
CVE-2026-32285 is a denial of service vulnerability in the Delete function of the jsonparser library. The function fails to properly validate offsets when processing malformed JSON input, leading to a negative slice index and a runtime panic. This issue has a CVSS score of 7.5 and is considered HIGH severity. The vulnerability requires verification and remediation to prevent potential denial of service attacks. Affected systems and dependencies require review and update. Defenders should prioritize verifying the jsonparser library version and applying patches or updates.
- Vendor
- github.com/buger/jsonparser
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-26
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-03-26
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for maintaining and securing systems that use the jsonparser library should assess exposure and prioritize verification and remediation. Affected operators, platforms, vulnerability-management, and security teams should review and update affected systems and dependencies. Defenders should also monitor for potential denial of service attacks and review compensating controls for exposed systems.
Why it matters
CVE-2026-32285 is a denial of service vulnerability in the jsonparser library that requires verification and remediation to prevent potential attacks.
- Denial of service attacks may occur if the vulnerability is exploited
- Verification of jsonparser library version and application of patches or updates is necessary
- Affected systems and dependencies require review and update
Technical summary
The Delete function in the jsonparser library fails to properly validate offsets when processing malformed JSON input, leading to a negative slice index and a runtime panic. This allows a denial of service attack. The vulnerability has a CVSS score of 7.5 and is considered HIGH severity. Defenders should prioritize verifying the jsonparser library version and applying patches or updates to prevent potential denial of service attacks. The vulnerability requires verification and remediation to prevent potential attacks.
Defensive priority
Defenders should prioritize verifying the jsonparser library version and applying patches or updates to prevent potential denial of service attacks.
Recommended defensive actions
- Verify the jsonparser library version and apply patches or updates
- Review and update affected systems and dependencies
- Monitor for potential denial of service attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the vulnerability, including its description, CVSS score, and affected versions. The jsonparser library is used in various systems and applications, and its vulnerability may lead to denial of service attacks. Defenders should verify the library version and apply patches or updates to prevent potential attacks. The vulnerability has a CVSS score of 7.5 and is considered HIGH severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-32285 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-32285
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-32285 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32285
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/buger/jsonparser/issues/275
[email protected] - Issue Tracking, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/golang/vulndb/issues/4514
[email protected] - Issue Tracking, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://pkg.go.dev/vuln/GO-2026-4514
[email protected] - Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:13548
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:17121
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:17123
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:19099
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:21769
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.