Skip to content

chore(deps): update module github.com/buger/jsonparser to v1.1.2 [security] (release-v2.9) - #6744

Merged
renovate-sh-app[bot] merged 1 commit into
release-v2.9from
renovate/release-v2.9-go-github.com-buger-jsonparser-vulnerability
Mar 26, 2026
Merged

chore(deps): update module github.com/buger/jsonparser to v1.1.2 [security] (release-v2.9)#6744
renovate-sh-app[bot] merged 1 commit into
release-v2.9from
renovate/release-v2.9-go-github.com-buger-jsonparser-vulnerability

Conversation

@renovate-sh-app

@renovate-sh-app renovate-sh-app Bot commented Mar 19, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/buger/jsonparser v1.1.1v1.1.2 age confidence

Denial of service in github.com/buger/jsonparser

GHSA-6g7g-w4f8-9c9x

More information

Details

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

buger/jsonparser (github.com/buger/jsonparser)

v1.1.2

Compare Source

What's Changed
New Contributors

Full Changelog: buger/jsonparser@v1.1.1...v1.1.2


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

Need help?

You can ask for more help in the following Slack channel: #proj-renovate-self-hosted. In that channel you can also find ADR and FAQ docs in the Resources section.

@renovate-sh-app renovate-sh-app Bot added dependencies Pull requests that update a dependency file gomod patch renovate Applied to PR's created by renovatebot labels Mar 19, 2026
@renovate-sh-app
renovate-sh-app Bot requested a review from joe-elliott as a code owner March 19, 2026 14:10
@renovate-sh-app
renovate-sh-app Bot requested a review from mdisibio as a code owner March 19, 2026 14:10
@renovate-sh-app
renovate-sh-app Bot enabled auto-merge (squash) March 19, 2026 14:10
…urity]

| datasource | package                     | from   | to     |
| ---------- | --------------------------- | ------ | ------ |
| go         | github.com/buger/jsonparser | v1.1.1 | v1.1.2 |


Signed-off-by: renovate-sh-app[bot] <219655108+renovate-sh-app[bot]@users.noreply.github.com>
@renovate-sh-app
renovate-sh-app Bot force-pushed the renovate/release-v2.9-go-github.com-buger-jsonparser-vulnerability branch from a9d1388 to df7c8d5 Compare March 26, 2026 23:13
@renovate-sh-app
renovate-sh-app Bot merged commit a6d511e into release-v2.9 Mar 26, 2026
24 checks passed
@renovate-sh-app
renovate-sh-app Bot deleted the renovate/release-v2.9-go-github.com-buger-jsonparser-vulnerability branch March 26, 2026 23:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file gomod patch renovate Applied to PR's created by renovatebot security update-patch

0 participants