6.2
CVE-2026-62866
- EPSS 0.19%
- Veröffentlicht 21.09.2026 16:51:18
- Zuletzt bearbeitet 24.09.2026 21:25:27
- Erkennungen
Dasel: Selector lexer panics on trailing whitespace in `parseCurRune`
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across trailing whitespace and then reads the source at the exhausted index without an end-of-input check. A selector ending in whitespace, including input passed through lexer.NewTokenizer(...).Tokenize() or dasel.Query, can therefore cause an index-out-of-range panic and terminate the process. This issue is fixed in version 3.11.2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTomWright
≫
Produkt
dasel
Version
>= 3.0.0, < 3.11.2
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.094 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.2 | 2.5 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-129 Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
https://github.com/TomWright/dasel/security/advisories/GHSA-65gg-g7rw-6cpc
https://github.com/TomWright/dasel/commit/eee03aec28d4a33d6138098d065b7b37b85e3c55
https://github.com/TomWright/dasel/releases/tag/v3.11.2