CVE-2026-37736: OWASP json-sanitizer vulnerability
Published Aug 28, 2026
·Updated
An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Affected Software
1 affected component
OWASP json-sanitizer=1.2.3
Event History
Aug 28, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What attacker capability is required to trigger the issue?
An attacker needs to supply crafted input that is processed by the JsonSanitizer.sanitize() component. The reported impact is denial of service.
2
Which release should be prioritized for investigation?
The issue is reported in OWASP json-sanitizer v1.2.3. The available information does not state whether earlier or later releases are affected.