Description
go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI specifications, causing fatal stack overflow that terminates the process and all in-flight requests.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Stack overflow causing denial of service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the jsonutils component of the go‑openapi/swag library, present in all releases before 0.27.1. The ordered JSON marshal and unmarshal logic recurses without a depth limit, causing a stack overflow when a deeply nested JSON document is processed. An attacker can trigger this by sending a specially crafted OpenAPI specification over the network. The resulting stack overflow terminates the process that is doing the parsing, bringing down the service and any other in‑flight requests, effectively causing a denial of service for all clients.

Affected Systems

The flaw affects the go‑openapi/swag package used in Go projects that consume or generate OpenAPI specifications. Any application incorporating go‑openapi/swag before version 0.27.1, such as API gateways, web services, or tooling that accepts OpenAPI descriptions, is susceptible. The affected product is the go‑openapi/swag library, with all versions older than 0.27.1, while 0.27.1 and later include the fix.

Risk and Exploitability

The CVSS score of 8.7 classifies this as a high severity vulnerability. The EPSS score of less than 1% indicates that, at present, the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring no authentication: an unauthenticated attacker can provoke a stack overflow by submitting a deeply nested JSON document to any endpoint that parses OpenAPI specifications. Once triggered, the process terminates, resulting in service downtime. Although the impact is significant, the lack of steganographic prerequisites or privileged execution limits the operational risk compared to pure remote code execution flaws.

Generated by OpenCVE AI on September 19, 2026 at 07:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the go‑openapi/swag library to version 0.27.1 or later, which implements a depth limit during ordered JSON marshal and unmarshal.
  • If upgrading is not immediately possible, add application‑level validation to reject JSON payloads exceeding a reasonable depth or size before invoking the swagger parsing functions.
  • Deploy the application behind a process supervision system or container orchestrator that can automatically restart a crashed worker, reducing service disruption if a stack overflow does occur.

Generated by OpenCVE AI on September 19, 2026 at 07:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Go-openapi
Go-openapi swag
Vendors & Products Go-openapi
Go-openapi swag

Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI specifications, causing fatal stack overflow that terminates the process and all in-flight requests.
Title go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal and Unmarshal
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T12:58:44.088Z

Reserved: 2026-09-17T22:45:30.211Z

Link: CVE-2026-93450

cve-icon Vulnrichment

Updated: 2026-09-18T12:58:35.541Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T00:17:49.230

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:00:13Z

Weaknesses