CVE-2026-33818
published 2026-08-13CVE-2026-33818: Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.46%
38.4th percentile
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
Affected
107 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 3scale-amp2 | 3scale-operator-bundle | — | — |
| advanced-cluster-security | rhacs-main-rhel8 | — | — |
| advanced-cluster-security | rhacs-main-rhel9 | — | — |
| albo | aws-load-balancer-operator | — | — |
| albo | aws-load-balancer-rhel8-operator | — | — |
| ansible-automation-platform-26 | receptor-rhel9 | — | — |
| ansible-automation-platform-27 | receptor-rhel9 | — | — |
| ansible-automation-platform | platform-operator-bundle | — | — |
| apache | thrift | — | — |
| build-of-trustee | trustee-rhel9-operator | — | — |
| buildah_project | buildah | — | — |
| cert-manager | jetstack-cert-manager-rhel9 | — | — |
| compliance | openshift-compliance-operator-bundle | — | — |
| compliance | openshift-selinuxd-rhel8 | — | — |
| confidential-containers | trustee | — | — |
| container-native-virtualization | kubemacpool-rhel9 | — | — |
| container-tools_rhel8 | buildah | — | — |
| container-tools_rhel8 | conmon | — | — |
| container-tools_rhel8 | containernetworking-plugins | — | — |
| container-tools_rhel8 | crun | — | — |
| container-tools_rhel8 | oci-seccomp-bpf-hook | — | — |
| container-tools_rhel8 | podman | — | — |
| container-tools_rhel8 | runc | — | — |
| container-tools_rhel8 | skopeo | — | — |
| container-tools_rhel8 | toolbox | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
ghsa_unreviewed·2026-08-14
CVE-2026-33818 Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
VulDB
Google Go up to 1.25.12/1.26.5 encoding-asn1 Unmarshal resource consumption
vuldb·2026-08-14
CVE-2026-33818 [LOW] Google Go up to 1.25.12/1.26.5 encoding-asn1 Unmarshal resource consumption
A vulnerability, which was classified as problematic, has been found in Google Go up to 1.25.12/1.26.5. Affected by this issue is the function Unmarshal of the component encoding-asn1. This manipulation causes resource consumption.
The identification of this vulnerability is CVE-2026-33818. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
Red Hat
encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
vendor_redhat·2026-08-13·CVSS 7.5
CVE-2026-33818 [HIGH] CWE-776 encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
A flaw was found in the `encoding/asn1` package in Go. An attacker could provide a specially crafted, deeply-nested Abstract Syntax Notation One (ASN.1) structure, leading to excessive recursion during the `Unmarshal` operation. This could result in stack exhaustion and a Denial of Service (DoS) condition.
Package: rhai/assisted-installer-rhel9 (Assisted Installer for Red Hat OpenShift Container Platform 2) - Affected
Package: albo/aws-load-balancer-operator (AWS Load Balancer Operator) - Affected
Package: albo/aws-load-balancer-rhel8-operator (AWS Load Balancer Operator) - Affected
Package: openshift-builds/openshift-builds-waiters-rhel9 (Builds for Red Hat OpenShift) - Affected
Package:
No detection rules found.
No public exploits indexed.
2026-08-13
Published