Junglewise Threat Intelligence

CVE-2026-33818: Go Unmarshal stack exhaustion in recursive structure parsing

CVE-2026-33818 · Severity: high · CVSS 7.5 · Published 2026-08-13

Technologies: go (Go). Vendors: Go.

Executive brief

Go's Unmarshal function, which parses structured data (such as JSON or XML) into program objects, is vulnerable to a denial-of-service attack when processing deeply-nested or recursive data structures. An attacker can craft malicious input that causes the parser to exhaust the call stack, crashing applications and disrupting service availability.

Technical details

The vulnerability is a stack exhaustion flaw in Go's Unmarshal function, which lacks proper recursion limits when parsing deeply-nested or recursive data structures. An attacker can supply malformed input with excessive nesting depth that triggers unbounded recursion in the unmarshaling logic. The attack requires no authentication and is network-reachable if the application exposes an endpoint that accepts and unmarshals untrusted data. Successful exploitation results in a denial of service through stack overflow, crashing the affected application. The vulnerability has been addressed by enforcing recursion depth limits in the Unmarshal implementation.

Affected products

  • Go Go <1.23 (estimated)

Timeline

  • 2026-08-13: disclosed

References