VDB
CVE-2026-33818
CVE-2026-33818
PUBLISHED
CVSS 7.5 HIGH
Reported by Go · Published August 13, 2026
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Go standard library | encoding/asn1 | 0, 1.26.0-0, 1.27.0-0 |
| chainguard | tigera-operator-1.37 | 0 |
| chainguard | tetragon | 0 |
| chainguard | gops | * |
| chainguard | crossplane-provider-aws-sagemaker-fips | 0 |
| wolfi | rancher-system-upgrade-controller | 0, 0, 0 |
| chainguard | ingress-nginx-controller-1.13 | * |
| wolfi | cert-manager-istio-csr | 0, 0, 0 |
| wolfi | crossplane-provider-aws-rds | 0, 0, 0 |
| wolfi | prometheus-operator | 0, 0, 0 |
| wolfi | dataplaneapi | 0, 0, 0 |
| chainguard | azurefile-csi-fips-1.34 | 0 |
| wolfi | amazon-cloudwatch-agent | *, *, * |
| wolfi | telegraf-1.37 | 0, 0, 0 |
| chainguard | crossplane-provider-aws-appsync-fips | 0 |
| chainguard | kubeflow-pipelines-fips | 0 |
| chainguard | prometheus-mongodb-exporter | 0, 0 |
| chainguard | smokescreen | 0, 0 |
| chainguard | nri-elasticsearch-fips | 0 |
| wolfi | runc | 0, 0, 0 |
…and 2807 more
Timeline
- Aug 13, 2026 CVE Published
- Aug 15, 2026 Coalition ESS Score
- Aug 20, 2026 Security Advisory
- Aug 24, 2026 EPSS Score