GHSA-x7f3-62pm-9p38
Dashboard / Vulnerabilities / GHSA-x7f3-62pm-9p38
GHSA-x7f3-62pm-9p38
Published: 20 May 2022Last Modified: 10 Sept 2026
Aliases:
Summary: Out of bounds memory access in github.com/open-policy-agent/opa
Details: An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-28946, https://github.com/open-policy-agent/opa/pull/4548, https://github.com/open-policy-agent/opa/commit/e9d3828db670cbe11129885f37f08cbf04935264, https://github.com/open-policy-agent/opa, https://pkg.go.dev/vuln/GO-2022-0587
Affected packages
Package
Name: github.com/open-policy-agent/opa
Purl: pkg:golang/github.com/open-policy-agent/opa
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.40.0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
