Impact
The vulnerability lies in the jsonutils component of the go‑openapi/swag library, present in all releases before 0.27.1. The ordered JSON marshal and unmarshal logic recurses without a depth limit, causing a stack overflow when a deeply nested JSON document is processed. An attacker can trigger this by sending a specially crafted OpenAPI specification over the network. The resulting stack overflow terminates the process that is doing the parsing, bringing down the service and any other in‑flight requests, effectively causing a denial of service for all clients.
Affected Systems
The flaw affects the go‑openapi/swag package used in Go projects that consume or generate OpenAPI specifications. Any application incorporating go‑openapi/swag before version 0.27.1, such as API gateways, web services, or tooling that accepts OpenAPI descriptions, is susceptible. The affected product is the go‑openapi/swag library, with all versions older than 0.27.1, while 0.27.1 and later include the fix.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high severity vulnerability. The EPSS score of less than 1% indicates that, at present, the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring no authentication: an unauthenticated attacker can provoke a stack overflow by submitting a deeply nested JSON document to any endpoint that parses OpenAPI specifications. Once triggered, the process terminates, resulting in service downtime. Although the impact is significant, the lack of steganographic prerequisites or privileged execution limits the operational risk compared to pure remote code execution flaws.
OpenCVE Enrichment