HIGH

CVE-2026-93450

2026-09-18 CVSS v3.1
CVSS
7.5

Description

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI specifications, causing fatal stack overflow that terminates the process and all in-flight requests.

Weakness (CWE)

CWE-674

EPSS Score

0.66%
Probability of exploitation in next 30 days
50.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE