DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

GHSA-8r3f-844c-mc37

Published

Last updated

https://github.com/advisories/GHSA-8r3f-844c-mc37

Severity

7.5

High

CVSS V3

Summary

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Description

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing