A malicious JSON patch can cause a panic due to an out-of-bounds write attempt. This can be used as a denial of service vector if exposed to arbitrary user input.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2021-0076" }
{ "imports": [ { "path": "github.com/evanphx/json-patch", "symbols": [ "Patch.Apply", "Patch.ApplyIndent", "partialArray.add" ] } ] }