CVE-2021-42248Regex Denial of Service in Tidwall Gjson

Severity
7.5HIGH
No vector
EPSS
No EPSS data
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateSep 10

Description

github.com/tidwall/gjson Vulnerable to REDoS attack GJSON is a Go package that provides a fast and simple way to get values from a json document. GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.

Affected Packages3 packages

🔴Vulnerability Details

4
OSV
Denial of service via maliciously crafted path in github.com/tidwall/gjson2022-08-15
OSV
Duplicate Advisory: ReDoS via crafted JSON input in GJSON2022-05-25
GHSA
Duplicate Advisory: ReDoS via crafted JSON input in GJSON2022-05-25
OSV
github.com/tidwall/gjson Vulnerable to REDoS attack2021-10-25

📋Vendor Advisories

1
Microsoft
CVE-2021-42248: NIST NVD Details: https://nvd2024-09-10