See how gjson project compares to other vendors in security performance
GJSON <=v1.6.5 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a crafted GET call.
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-ppj4-34rq-v8j9. This link is maintained to preserve external references.
Original Description GJSON <= 1.9.2 allows attackers to cause a redos via crafted JSON input.
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
GJSON <1.6.5 allows attackers to cause a denial of service (remote) via crafted JSON.
GJSON before 1.6.4 allows attackers to cause a denial of service via crafted JSON.