CVE-2026-32285
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
- Affected products
- Go, Grafana Alloy, Logging Subsystem For Red Hat Openshift, Logging Subsystem For Red Hat Openshift 6.4, Multicluster Global Hub 1.3.4, Multicluster Global Hub 1.4.5, Multicluster Global Hub 1.5.4, Multicluster Global Hub 1.5.6
- Jsonparser Project Jsonparser
- < 1.1.2
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.8% (51th percentile)
- Weakness
- CWE-129, CWE-1285
- NVD status
- Modified
- Published
- 2026-03-26
CVE-2026-32285 at NVD
No indexed exploits for CVE-2026-32285 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-32285 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.