The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.
{ "binaries": [ { "binary_name": "golang-github-buger-jsonparser-dev", "binary_version": "0.0~git20170705.0.9addec9-1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-32285.json"
{ "binaries": [ { "binary_name": "golang-github-buger-jsonparser-dev", "binary_version": "0.0~git20170705.0.9addec9-2" } ] }
{ "binaries": [ { "binary_name": "golang-github-buger-jsonparser-dev", "binary_version": "1.1.1-2" } ] }