{"id":"GHSA-65gg-g7rw-6cpc","summary":"Dasel: Selector lexer panics on trailing whitespace in `parseCurRune`","details":"Same panic class as GHSA-m5j3-4634-c2vq and GHSA-m6xr-fvfg-5g64, sister site on the same function. Trigger is any selector ending in whitespace: `dasel query 'a '` panics at `selector/lexer/tokenize.go:60`.\n\nThe whitespace-skip loop right above (lines 55-57) advances `p.i` to `p.srcLen` when the input is all-whitespace or whitespace-trailing. The very next line reads `p.src[p.i]` without a bounds check.\n\n## Vulnerable code\n\n`selector/lexer/tokenize.go:53-74` (v3.11.0):\n\n```go\nfunc (p *Tokenizer) parseCurRune() (Token, error) {\n\t// Skip over whitespace\n\tfor p.i \u003c p.srcLen && unicode.IsSpace(rune(p.src[p.i])) {\n\t\tp.i++\n\t}\n\n\t// Skip over comments\n\tif p.src[p.i] == '/' && p.i+1 \u003c p.srcLen && p.src[p.i+1] == '/' {\n\t\t// ...\n```\n\nLines 69-71 right below already do the bounds check after the comment-skip path. The whitespace-only path slipped past it.\n\n## Reproduce\n\n```\n$ echo '{\"a\":1}' | dasel query -i json 'a '\npanic: runtime error: index out of range [2] with length 2\n\ngoroutine 1 [running]:\ngithub.com/tomwright/dasel/v3/selector/lexer.(*Tokenizer).parseCurRune(...)\n\tselector/lexer/tokenize.go:60\ngithub.com/tomwright/dasel/v3/selector/lexer.(*Tokenizer).Next(...)\ngithub.com/tomwright/dasel/v3/selector/lexer.(*Tokenizer).Tokenize(...)\ngithub.com/tomwright/dasel/v3/selector.Parse(...)\ngithub.com/tomwright/dasel/v3/execution.ExecuteSelector(...)\n```\n\nOther inputs that hit it: `'   '`, `$'a\\t'`, `$'a\\n'`, `'a ?? '`, `'a + '`. Any token (or no token) followed by whitespace.\n\nReachable directly from the library too - `dasel.Query(ctx, input, \"a \")` panics the same way. Project-style test reproducer that fails on current `main`:\n\n```go\n// drop into selector/lexer/ as tokenize_trailing_ws_test.go\npackage lexer_test\n\nimport (\n\t\"testing\"\n\t\"github.com/tomwright/dasel/v3/selector/lexer\"\n)\n\nfunc TestTokenize_TrailingWhitespacePanic(t *testing.T) {\n\tdefer func() {\n\t\tif r := recover(); r != nil {\n\t\t\tt.Fatalf(\"Tokenize panicked: %v\", r)\n\t\t}\n\t}()\n\t_, _ = lexer.NewTokenizer(\"a \").Tokenize()\n}\n```\n\n## Impact\n\nProcess crash, no auth, no preconditions. Same severity tier as the two May 13 advisories on this file.\n\n## Affected versions\n\nAll v3.x. The whitespace-skip loop was added in `78fcca9` (Dasel V3, ~9 months ago); line 60's indexing landed in `9bfe966` (~6 months ago). Reproduced on `github.com/tomwright/dasel/v3@v3.11.0`.\n\n## Suggested fix\n\nOne line, between the whitespace-skip loop and the comment-skip access. Same shape as lines 69-71:\n\n```go\nfunc (p *Tokenizer) parseCurRune() (Token, error) {\n\tfor p.i \u003c p.srcLen && unicode.IsSpace(rune(p.src[p.i])) {\n\t\tp.i++\n\t}\n\n\tif p.i \u003e= p.srcLen {\n\t\treturn NewToken(EOF, \"\", p.i, 0), nil\n\t}\n\n\tif p.src[p.i] == '/' && p.i+1 \u003c p.srcLen && p.src[p.i+1] == '/' {\n```\n\n## Prevalence\n\nThe other two cases in this class shipped fixes two weeks ago; this one wasn't covered in those patches. I checked the rest of `parseCurRune` for other unguarded direct-access points after a `pos++` - nothing else stood out. A `testing.F` harness on `lexer.NewTokenizer(s).Tokenize()` catches all three with trivially short inputs and would close the class.","aliases":["CVE-2026-62866","GO-2026-6548"],"modified":"2026-10-01T20:55:58.390167711Z","published":"2026-09-22T19:52:16Z","database_specific":{"cwe_ids":["CWE-129"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-22T19:52:16Z","nvd_published_at":"2026-09-21T17:17:38Z"},"references":[{"type":"WEB","url":"https://github.com/TomWright/dasel/security/advisories/GHSA-65gg-g7rw-6cpc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62866"},{"type":"WEB","url":"https://github.com/TomWright/dasel/commit/eee03aec28d4a33d6138098d065b7b37b85e3c55"},{"type":"PACKAGE","url":"https://github.com/TomWright/dasel"},{"type":"WEB","url":"https://github.com/TomWright/dasel/releases/tag/v3.11.2"}],"affected":[{"package":{"name":"github.com/tomwright/dasel/v3","ecosystem":"Go","purl":"pkg:golang/github.com/tomwright/dasel/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.11.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-65gg-g7rw-6cpc/GHSA-65gg-g7rw-6cpc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}