Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-42836

24
FAUCET Score

CVE-2021-42836 is a Regular Expression Denial of Service (ReDoS) vulnerability affecting GJSON versions prior to 1.9.3. This vulnerability carries a high CVSS score of 7.5, indicating a significant impact where an unauthenticated attacker can remotely trigger a denial of service. While no active exploitation, public exploit code, or significant community discussion has been observed, the potential for service disruption remains.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.9.3CPE matchmatch criteria
cpe:2.3:a:gjson_project:gjson:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.25%
Probability of exploitation in next 30 days
EPSS Percentile
81.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0225 is in the 66th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/tidwall/gjsonFixed in: 1.9.3
microsoftpatch availablevia msrc
Product: 19877-17084Fixed in: 2.14.0-1
microsoftpatch availablevia msrc
Product: 17761-17084Fixed in: 2.14.0-1
microsoftpatch availablevia msrc
Product: azl3 keda 2.4.0-15 on Azure Linux 3.0Fixed in: 2.14.0-1
microsoftpatch availablevia msrc
Product: azl3 keda 2.14.0-1 on Azure Linux 3.0Fixed in: 2.14.0-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2.14.0-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2.14.0-1

Vendor Advisories (3)

microsoft2024-Sep/CVE-2021-42836

CVE-2021-42836

Sep 10, 2024
goGHSA-ppj4-34rq-v8j9high

github.com/tidwall/gjson Vulnerable to REDoS attack

Oct 25, 2021
microsoft2021-Oct/CVE-2021-42836Important

GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.

Oct 12, 2021

References

github.com / tidwall/gjson/commit/590010fdac311cc8990ef5c97448d4fec8f29944
PatchThird Party Advisory
github.com / tidwall/gjson/commit/77a57fda87dca6d0d7d4627d512a630f89a91c96
PatchThird Party Advisory
github.com / tidwall/gjson/compare/v1.9.2...v1.9.3
Release NotesThird Party Advisory
github.com / tidwall/gjson/issues/236
ExploitIssue TrackingThird Party Advisory
github.com / tidwall/gjson/issues/237
ExploitIssue TrackingPatchThird Party Advisory