PT-2026-96157 · Dasel · Dasel

CVE-2026-62866

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Dasel versions 3.0.0 through 3.11.1
Description In the parseCurRune function within selector/lexer/tokenize.go, the input index advances across trailing whitespace and reads the source at the exhausted index without performing an end-of-input check. A selector ending in whitespace, when processed via lexer.NewTokenizer(...).Tokenize() or dasel.Query, can trigger an index-out-of-range panic, leading to process termination.
Recommendations Update to version 3.11.2.

Exploit

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62866
GHSA-65GG-G7RW-6CPC

Affected Products

Dasel