Root has patched CVE-2026-32285 in the rootio-github.com/buger/jsonparser package for Root:Go. Multiple fixed versions available.
{ "source": "Root", "distro_version": "", "distro": "gobinary" }
"v1.1.1-root.io.1"
"https://api.root.io/external/osv/ROOT-APP-GOBINARY-CVE-2026-32285.json"
[ "v1.1.1-root.io.1" ]
""
true
1.0