{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/go-openapi/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:go-openapi:swag:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-93450"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["swag (\u003c 0.27.1)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["go-openapi"],"content_html":"\u003cp\u003eThe go-openapi/swag library, specifically the jsonutils component in versions prior to 0.27.1, contains a critical stack overflow vulnerability. The flaw arises from unbounded recursion during the parsing and serialization of ordered JSON structures, which lacks a defined depth limit. By submitting a specially crafted, deeply nested JSON document to any service or application utilizing the library to process OpenAPI specifications, a remote unauthenticated attacker can trigger a fatal stack overflow. This leads to an immediate crash of the host process, effectively terminating all in-flight requests and causing a denial-of-service condition. Because this library is commonly integrated into API gateways, middleware, and documentation generators, the potential impact across microservices architectures is significant.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a persistent denial-of-service for any service using the vulnerable library. The vulnerability is triggered by a single request, meaning minimal resources are required for an attacker to disrupt service availability. All deployments of applications using go-openapi/swag versions before 0.27.1 are susceptible to this vector.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for development and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the go-openapi/swag dependency to version 0.27.1 or later immediately to include the required depth limiting in the jsonutils component.\u003c/li\u003e\n\u003cli\u003eReview all internet-facing services that accept OpenAPI or JSON-based configurations and apply input validation to limit JSON nesting depth as a defense-in-depth measure until the library is patched.\u003c/li\u003e\n\u003cli\u003eImplement crash monitoring and automated service restarts in orchestrators (such as Kubernetes) to mitigate the impact of the resulting process termination.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T02:01:32Z","date_published":"2026-09-18T02:01:32Z","id":"https://feed.craftedsignal.io/briefs/2026-09-go-openapi-swag-dos/","summary":"The go-openapi/swag library is vulnerable to a stack overflow in its jsonutils component, allowing remote unauthenticated attackers to cause a denial-of-service by submitting deeply nested JSON documents.","title":"Denial of Service in go-openapi/swag via Stack Overflow","url":"https://feed.craftedsignal.io/briefs/2026-09-go-openapi-swag-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Go-Openapi","version":"https://jsonfeed.org/version/1.1"}