{"id":"GO-2022-0592","details":"A maliciously crafted path can cause Get and other query functions\nto consume excessive amounts of CPU and time.\n","modified":"2022-08-19T22:21:47Z","published":"2022-08-15T18:06:07Z","withdrawn":"2024-05-15T05:37:10.775601Z","references":[{"type":"FIX","url":"https://github.com/tidwall/gjson/commit/77a57fda87dca6d0d7d4627d512a630f89a91c96"},{"type":"WEB","url":"https://github.com/tidwall/gjson/issues/237"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-42248"},{"type":"WEB","url":"https://github.com/advisories/GHSA-c9gm-7rfj-8w5h"}],"affected":[{"package":{"name":"github.com/tidwall/gjson","ecosystem":"Go","purl":"pkg:golang/github.com/tidwall/gjson"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.9.3"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/tidwall/gjson","symbols":["Get","GetBytes","GetMany","GetManyBytes","Result.Get","queryMatches"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2022-0592.json","url":"https://pkg.go.dev/vuln/GO-2022-0592"}}],"schema_version":"1.7.3"}