The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade cri-tools-debuginfoUpgrade cri-tools | May 20, 2026 | May 20, 2026 |
| Splunk | — | Upgrade Splunk Enterprise to version 10.0.8Upgrade Splunk Enterprise to version 9.4.13Upgrade Splunk Enterprise to version 10.4.1Upgrade Splunk Enterprise to version 10.2.5 | Jul 16, 2026 | Mar 26, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub