CVE-2026-32285
published 2026-03-26CVE-2026-32285: The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.75%
51.2th percentile
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | golang-github-buger-jsonparser | < golang-github-buger-jsonparser 1.1.2-1 (forky) | golang-github-buger-jsonparser 1.1.2-1 (forky) |
| github.com | buger_jsonparser | >= 0 < 1.1.2 | 1.1.2 |
| github.com | buger_jsonparser_github.com_buger_jsonparser | < 1.1.2 | 1.1.2 |
| jsonparser_project | jsonparser | < 1.1.2 | 1.1.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
buger jsonparser Delete out-of-bounds (Issue 275 / Nessus ID 304167)
vuldb·2026-07-01·CVSS 7.5
CVE-2026-32285 [HIGH] buger jsonparser Delete out-of-bounds (Issue 275 / Nessus ID 304167)
A vulnerability marked as problematic has been reported in buger jsonparser. This affects the function Delete. The manipulation leads to out-of-bounds read.
This vulnerability is referenced as CVE-2026-32285. Remote exploitation of the attack is possible. No exploit is available.
OSV
CVE-2026-32285: The Delete function fails to properly validate offsets when processing malformed JSON input
osv·2026-03-26·CVSS 7.5
CVE-2026-32285 [HIGH] CVE-2026-32285: The Delete function fails to properly validate offsets when processing malformed JSON input
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
GHSA
Denial of service in github.com/buger/jsonparser
ghsa·2026-03-18
CVE-2026-32285 [HIGH] CWE-125 Denial of service in github.com/buger/jsonparser
Denial of service in github.com/buger/jsonparser
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
OSV
Denial of service in github.com/buger/jsonparser
osv·2026-03-18
CVE-2026-32285 [HIGH] Denial of service in github.com/buger/jsonparser
Denial of service in github.com/buger/jsonparser
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
Red Hat
github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input
vendor_redhat·2026-03-26·CVSS 7.5
CVE-2026-32285 [HIGH] CWE-1285 github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input
github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
A flaw was found in github.com/buger/jsonparser. The Delete function, when processing malformed JSON input, fails to properly validate offsets. This vulnerability can lead to a negative slice index and a runtime panic, allowing a remote attacker to cause a denial of service (DoS) by providing specially crafted JSON data.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployme
Debian
CVE-2026-32285: golang-github-buger-jsonparser - The Delete function fails to properly validate offsets when processing malformed...
vendor_debian·2026·CVSS 7.5
CVE-2026-32285 [HIGH] CVE-2026-32285: golang-github-buger-jsonparser - The Delete function fails to properly validate offsets when processing malformed...
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.1.2-1)
sid: resolved (fixed in 1.1.2-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-32285 rclone: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-32285 [HIGH] CVE-2026-32285 rclone: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
CVE-2026-32285 rclone: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-b6061d5edc (rclone-1.74.0-2.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-b6061d5edc
---
FEDORA-EPEL-2026-a29802e574 (rclone-1.74.0-2.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-a29802e574
---
FEDORA-EPEL-2026-2d051ede2c (rclone-1.74.0-2.el10_2) has been submitted as an update to Fedora EPEL 1
Bugzilla
CVE-2026-32285 apptainer: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-32285 [HIGH] CVE-2026-32285 apptainer: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
CVE-2026-32285 apptainer: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-d516d12934 (apptainer-1.5.0-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-d516d12934
---
FEDORA-2026-6c547e9f64 (apptainer-1.5.0-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-6c547e9f64
---
FEDORA-2026-db5621b65e (apptainer-1.5.0-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.or
Bugzilla
CVE-2026-32285 singularity-ce: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-32285 [HIGH] CVE-2026-32285 singularity-ce: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
CVE-2026-32285 singularity-ce: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-82e8b5fef4 (singularity-ce-4.4.2-1.el10_2) has been submitted as an update to Fedora EPEL 10.2.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-82e8b5fef4
---
FEDORA-EPEL-2026-15e8597d17 (singularity-ce-4.4.2-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-15e8597d17
---
FEDORA-EPEL-2026-d9f99fbd40 (singularity-ce-4.4.2-1.el9) has been submitt
Bugzilla
CVE-2026-32285 rclone: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-32285 [HIGH] CVE-2026-32285 rclone: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
CVE-2026-32285 rclone: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-a29802e574 (rclone-1.74.0-2.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-a29802e574
---
FEDORA-EPEL-2026-a29802e574 has been pushed to the Fedora EPEL 10.3 testing repository.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-a29802e574
See also https://fedoraproject.org/wiki/QA:Updates_Testing for more
Bugzilla
CVE-2026-32285 apptainer: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-32285 [HIGH] CVE-2026-32285 apptainer: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
CVE-2026-32285 apptainer: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This module is only used in end-2-end tests and not in any released code. The main and release-1.5 branches have been updated.
Bugzilla
CVE-2026-32285 prometheus: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-32285 [HIGH] CVE-2026-32285 prometheus: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
CVE-2026-32285 prometheus: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-1ce4512bd4 (prometheus-3.11.0-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-1ce4512bd4
---
FEDORA-EPEL-2026-1ce4512bd4 has been pushed to the Fedora EPEL 10.3 testing repository.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-1ce4512bd4
See also https://fedoraproject.org/wiki/QA:Updates_Testing f
Bugzilla
CVE-2026-32285 jfrog-cli: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-32285 [HIGH] CVE-2026-32285 jfrog-cli: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
CVE-2026-32285 jfrog-cli: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This is fixed in jfrog-cli 2.98.0 or later, where jsonparser was updated to 1.1.2.
---
FEDORA-EPEL-2026-b5304cc714 (jfrog-cli-2.98.0-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-b5304cc714
Bugzilla
CVE-2026-32285 containernetworking-plugins: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-32285 [HIGH] CVE-2026-32285 containernetworking-plugins: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
CVE-2026-32285 containernetworking-plugins: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
❯ go mod why -m github.com/buger/jsonparser
# github.com/buger/jsonparser
github.com/containernetworking/plugins/pkg/hns
github.com/buger/jsonparser
According to https://pkg.go.dev/vuln/GO-2026-4514 golang before before v1.1.2 is needed (released more than 10 years ago). This should not be an issue with current Go on Fedora
Bugzilla
CVE-2026-32285 singularity-ce: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-32285 [HIGH] CVE-2026-32285 singularity-ce: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
CVE-2026-32285 singularity-ce: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This module is only used in end-2-end tests and not in any released code. The main and release-1.5 branches have been updated.
Bugzilla
CVE-2026-32285 prometheus: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-32285 [HIGH] CVE-2026-32285 prometheus: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
CVE-2026-32285 prometheus: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-1ce4512bd4 (prometheus-3.11.0-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-1ce4512bd4
---
FEDORA-EPEL-2026-1ce4512bd4 has been pushed to the Fedora EPEL 10.3 testing repository.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-1ce4512bd4
See also https://fedoraproject.org/wiki/QA:Updates_Testing for
Bugzilla
CVE-2026-32285 github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input
bugzilla·2026-03-26·CVSS 7.5
CVE-2026-32285 [HIGH] CVE-2026-32285 github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input
CVE-2026-32285 github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
Wiz
CVE-2026-32285 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.5
CVE-2026-32285 [LOW] CVE-2026-32285 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32285 :
MinIO vulnerability analysis and mitigation
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
Source : NVD
## 7.5
Score
Published March 26, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
MinIO
Rclone
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
redpanda-25.3
maru
Sources
NVD
Chainguard Has Fix Added at: Apr 02, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 29, 2026
Debian 14 Severity HIGH Has Fix Added at: Mar 29, 2026
E
Wiz
CVE-2026-33809 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2026-33809 [CRITICAL] CVE-2026-33809 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33809 :
Rclone vulnerability analysis and mitigation
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
Source : NVD
## 5.3
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Rclone
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
go-toolset:rhel8::golang-tests
golang-bin
Sources
NVD
Chainguard Has Fix Added at: Mar 31, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 29, 2026
Debian 14 Severity MEDIUM Has Fix Added at: Mar 29
https://github.com/buger/jsonparser/issues/275https://github.com/golang/vulndb/issues/4514https://pkg.go.dev/vuln/GO-2026-4514https://access.redhat.com/errata/RHSA-2026:13548https://access.redhat.com/errata/RHSA-2026:17121https://access.redhat.com/errata/RHSA-2026:17123https://access.redhat.com/errata/RHSA-2026:19099https://access.redhat.com/errata/RHSA-2026:21769https://access.redhat.com/errata/RHSA-2026:22347https://access.redhat.com/errata/RHSA-2026:22423https://access.redhat.com/errata/RHSA-2026:23345https://access.redhat.com/errata/RHSA-2026:34364https://access.redhat.com/errata/RHSA-2026:35111https://access.redhat.com/errata/RHSA-2026:36882https://access.redhat.com/errata/RHSA-2026:7191https://access.redhat.com/errata/RHSA-2026:9385https://access.redhat.com/security/cve/CVE-2026-32285https://bugzilla.redhat.com/show_bug.cgi?id=2451846https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32285.jsonhttps://securityinfinity.com/research/buger-jsonparser-negative-slice-panic-dos-2026
2026-03-26
Published