CVE-2026-32285 describes a denial of service vulnerability where a Delete function fails to properly validate offsets in malformed JSON input, leading to a runtime panic. While specific affected products are not broadly listed, an update for govulncheck-vulndb addresses this issue. Rated 7.5 HIGH, this vulnerability has a low attack complexity and can be exploited over the network without authentication, leading to a high impact on availability. There is no evidence of active exploitation, nor are public exploit modules available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one security update identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.2CPE matchmatch criteria | cpe:2.3:a:jsonparser_project:jsonparser:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.