Skip to content

chore(deps): update module github.com/buger/jsonparser to v1.1.2 [security]#1943

Merged
Prashansa-K merged 1 commit into
mainfrom
renovate/go-github.com-buger-jsonparser-vulnerability
Mar 23, 2026
Merged

chore(deps): update module github.com/buger/jsonparser to v1.1.2 [security]#1943
Prashansa-K merged 1 commit into
mainfrom
renovate/go-github.com-buger-jsonparser-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Mar 20, 2026

This PR contains the following updates:

Package Change Age Confidence
github.com/buger/jsonparser v1.1.1v1.1.2 age confidence

GitHub Vulnerability Alerts

GHSA-6g7g-w4f8-9c9x

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.


Denial of service in github.com/buger/jsonparser

GHSA-6g7g-w4f8-9c9x

More information

Details

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

buger/jsonparser (github.com/buger/jsonparser)

v1.1.2

Compare Source

What's Changed

New Contributors

Full Changelog: buger/jsonparser@v1.1.1...v1.1.2


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Mar 20, 2026
@CLAassistant
Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

1 similar comment
@CLAassistant
Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@codecov-commenter
Copy link
Copy Markdown

codecov-commenter commented Mar 20, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 33.46%. Comparing base (ea99142) to head (8c05186).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #1943      +/-   ##
==========================================
- Coverage   33.51%   33.46%   -0.05%     
==========================================
  Files          76       76              
  Lines        6726     6726              
==========================================
- Hits         2254     2251       -3     
- Misses       4293     4295       +2     
- Partials      179      180       +1     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@renovate renovate Bot force-pushed the renovate/go-github.com-buger-jsonparser-vulnerability branch 4 times, most recently from 52c338b to 432e09b Compare March 23, 2026 12:26
…urity]

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate Bot force-pushed the renovate/go-github.com-buger-jsonparser-vulnerability branch from 432e09b to 8c05186 Compare March 23, 2026 12:29
@Prashansa-K Prashansa-K enabled auto-merge (squash) March 23, 2026 12:30
@Prashansa-K Prashansa-K merged commit 23d8efa into main Mar 23, 2026
38 of 39 checks passed
@Prashansa-K Prashansa-K deleted the renovate/go-github.com-buger-jsonparser-vulnerability branch March 23, 2026 12:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants