—
GO-2026-5157
hjson stack exhaustion vulnerability in github.com/hjson/hjson-go
Quick fix
GO-2026-5157 — github.com/hjson/hjson-go/v4: upgrade to the fixed version with the command below.
go get github.com/hjson/hjson-go/v4@v4.5.0Details
hjson stack exhaustion vulnerability in github.com/hjson/hjson-go
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hjson/hjson-go
Introduced in:
0No fixed version published yet for github.com/hjson/hjson-go (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/hjson/hjson-go/v4
Introduced in:
0Fixed in: 4.5.0Fix
go get github.com/hjson/hjson-go/v4@v4.5.0References
- https://github.com/advisories/GHSA-5wfc-hjrc-gq87[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2023-34620[ADVISORY]
- https://github.com/hjson/hjson-go/commit/326599cebc6ef759892f473bf1439b98466a99fa[FIX]
- https://github.com/hjson/hjson-go/pull/67[FIX]
- https://github.com/hjson/hjson-cpp/pull/54[WEB]
- https://github.com/hjson/hjson-java/issues/24[WEB]
- https://github.com/hjson/hjson-php/commit/2d1b8b4b158a8d841f3a228f267c7cd84fe5a4fa[WEB]
- https://github.com/hjson/hjson-php/pull/45[WEB]