Github · Swag · CVE-2026-93450
**Name of the Vulnerable Software and Affected Versions**
go-openapi/swag jsonutils versions prior to 0.27.1
**Description**
A stack overflow issue exists in ordered JSON parsing and serialization caused by unbounded recursion without a depth limit. Remote unauthenticated attackers can exploit this by submitting deeply nested JSON documents to services that accept OpenAPI specifications. This results in a fatal stack overflow that terminates the process and drops all in-flight requests.
**Recommendations**
Update to version 0.27.1.