VDB
Sign up
MEDIUM5.9

GHSA-c653-6hhg-9x92

go-ipld-prime/codec/json may panic if asked to encode bytes

Quick fix

GHSA-c653-6hhg-9x92 — github.com/ipld/go-ipld-prime: upgrade to the fixed version with the command below.

go get github.com/ipld/go-ipld-prime@v0.19.0

Details

`go-ipld-prime` is a series of Go interfaces for manipulating IPLD data and a Go module that contains the `go-ipld-prime/codec/json` codec.

### Impact

Encoding data which contains a `Bytes` kind Node will pass a `Bytes` token to the JSON encoder which will panic as it doesn't expect to receive `Bytes` tokens. Such an encoding should be treated as an error, as plain JSON should not be able to encode Bytes.

**This only impacts uses of the "json" codec, "dag-json" is not impacted.** Use of "json" as a decoder is not impacted.

### Patches

Fixed in v0.19.0.

### Workarounds

Prefer the "dag-json" codec which has the ability to [encode bytes](https://ipld.io/specs/codecs/dag-json/spec/#bytes).

### References

See fix in [#472](https://github.com/ipld/go-ipld-prime/pull/472)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/ipld/go-ipld-prime
Introduced in: 0Fixed in: 0.19.0
Fixgo get github.com/ipld/go-ipld-prime@v0.19.0

References