CVE-2026-34043

Aliases:GHSA-qj8w-gfj5-8c6vDEBIAN-CVE-2026-34043CGA-33rf-jqx7-x88qCGA-3rf8-cw46-7g4qCGA-3xgf-32xp-9v4vCGA-55f4-73c6-42vwCGA-5mmp-w6vq-f6xvCGA-5r44-9227-46rfCGA-5wvj-jqpq-4jx8CGA-6q5p-g69f-6m96CGA-6rjq-5mmp-jh9xCGA-7x2f-gf2v-34vmCGA-97cj-27g8-ff3pCGA-cfg2-9w9r-rrjxCGA-hp6m-77gm-wf7pCGA-hvrj-8328-w94qCGA-jwqx-77ff-327xCGA-mf3p-35j6-97c8CGA-p8fv-f22h-hmcxCGA-22qx-6r4x-m9r3CGA-27x3-f632-fwrhCGA-29wq-637v-jpg6CGA-2c23-c8gh-wxwxCGA-2gxr-h9q2-8mm7CGA-2h7c-9cwj-w36gCGA-34q3-jhh6-2gwwCGA-34xr-c5r5-77jxCGA-37r9-7q44-6g9jCGA-3g5p-rff2-pg63CGA-3gx7-v4jc-9mw4CGA-3r5q-pv25-xrj2CGA-3w8v-hgg7-mjxvCGA-437f-p8rq-8pwpCGA-46w7-jrx8-x67vCGA-47xm-chwf-3j2rCGA-4ccw-3q29-gwgfCGA-4f2w-5f84-28j5CGA-4g4p-r9p9-39jrCGA-4jr2-v5j4-7gjqCGA-4r3q-xwh9-97g7CGA-4wh4-qjg4-pqmmCGA-4wr5-jf96-9f57CGA-55hw-2w3j-mgghCGA-5934-q38v-372jCGA-5rr2-55c2-cx83CGA-629c-c58r-8w89CGA-6c7q-3fhw-ch98CGA-6g42-ghx2-9g3pCGA-6gp8-7gqh-gg72CGA-6p4j-xjgq-7wjwCGA-6p66-prpx-f49gCGA-6qg8-c8xv-3rhqCGA-6r7p-fr59-mv2hCGA-6vq6-m4cm-rf2wCGA-6wwf-9459-rhv4CGA-79wm-v6v9-qfm5CGA-7mr5-r3wf-4p8pCGA-7r2c-crx9-988jCGA-7x5f-f9r9-j5pqCGA-874h-rg63-p9p8CGA-874v-4w37-pv34CGA-8cfg-8q4v-qf4mCGA-8mm9-pm92-jfcmCGA-94fh-m47p-r7q9CGA-95rp-w89q-88rxCGA-9699-4r6f-qg2qCGA-9vjv-g6h8-fw6vCGA-c59q-3mwf-vrrhCGA-c7m2-5rgp-rvwjCGA-c9j5-2pmr-5v6vCGA-chvm-vppj-g5j7CGA-cwmr-fj34-7wh7CGA-cwwf-qpr7-ppxxCGA-f393-f9wq-5w2qCGA-f769-g679-m3g6CGA-fcvw-m7x4-xrc6CGA-ffq4-2q5h-hrr4CGA-ffwp-533w-3mx8CGA-fhvx-4q94-vppvCGA-fmhm-jvw3-6237CGA-g484-7fwp-qj56CGA-g8w2-838r-v8qxCGA-gf23-7r74-ggh8CGA-gfgh-rvcc-xfj2CGA-gg26-m8pp-rmvgCGA-gh35-rj4f-m293CGA-h229-9qvp-mqwvCGA-h3vw-x4mh-mqgcCGA-h4rr-829p-cc75CGA-hcf7-mqc5-7qpvCGA-hf38-cq4c-7w8wCGA-hvj5-whfg-8r6rCGA-hxv6-8x8j-rqpwCGA-j72m-666g-4vg5CGA-j9wh-8ppp-p3g3CGA-jf95-c4w8-fgj2CGA-jpjh-7388-99x3CGA-m52f-fqf8-v9f9CGA-m6vq-h7cr-wpc8CGA-mf4c-h7j9-78x7CGA-mf6q-4c9f-87mvCGA-mjw6-98mw-c74gCGA-mpqg-97v4-3c3vCGA-mpx8-j3v8-mxx7CGA-mq8v-786h-8wr7CGA-mqfp-7qwj-4vfpCGA-mrhj-78mf-ghqwCGA-mrwx-5xjj-q5jjCGA-p23j-6mr9-9v3gCGA-p336-wm4w-2fp6CGA-p3gh-jfr9-chchCGA-p6gf-484c-3mr9CGA-p6v6-9276-9vgvCGA-p7xp-qh68-3753CGA-p8ch-7297-6h4wCGA-ph64-jmp3-mm8qCGA-phgm-vqmr-9fv4CGA-pprj-2xr8-fwq2CGA-pvv7-vj7h-7ggrCGA-q24w-6xqv-w4qhCGA-q644-c28j-vrwhCGA-q7jg-8hpq-v668CGA-q9fm-fp7f-j58hCGA-qjh4-64gm-wx8mCGA-qjwm-prx5-vxh4CGA-r57c-wwgv-89r5CGA-r6v7-9v2c-229cCGA-r7wj-6wrc-q7pgCGA-r8h4-6fhm-hmr8CGA-rpr6-j92c-2h7jCGA-rvp4-q9f8-xhr9CGA-rwfw-v535-p46hCGA-v2jg-j7hc-9m5jCGA-v436-pvvr-cxjhCGA-vcx4-5r7j-9hc4CGA-vg2g-4rx2-3693CGA-vgcv-cqjv-2rxfCGA-vq24-9j8c-g755CGA-vq3q-cfh7-67cvCGA-w3rh-8q7q-77rcCGA-w4c4-rf6c-qfjwCGA-w9j8-63h9-vvmfCGA-whv5-w9g7-2973CGA-wjp4-5h8h-rx3qCGA-wr5f-j54p-xrpqCGA-x3gx-2hj2-r6rgCGA-x4r3-94pw-w9xqCGA-x67j-2j4q-3w5hCGA-x9pq-j2q9-97j6CGA-xc9x-jw4f-38vxCGA-xcp2-g57m-pw2wCGA-xg66-xjj9-9m84CGA-xr49-2q63-vf8pCGA-xxch-9cvr-gm2qCGA-hrvw-rc7p-hj8wCGA-jfh7-qq87-85jh
Advisory lineage Upstream: 0 Downstream: 8
Analyzed
Published: 31 Mar 2026, 01:48
Last modified:31 Mar 2026, 13:55

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.47% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

31 Mar 2026, 01:48
Published
Vulnerability first disclosed
31 Mar 2026, 13:55
Last Modified
Vulnerability information updated

Description

Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU exhaustion. When serializing a specially crafted "array-like" object (an object that inherits from Array.prototype but has a very large length property), the process enters an intensive loop that consumes 100% CPU and hangs indefinitely. This issue has been patched in version 7.0.5.

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.47% Percentile: 40%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

  • CWE-834Excessive Iteration

    The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardarangodb-3.11

    < 3.11.14.5-r4

  • chainguardarangodb-3.12

    all | < 3.12.11-r1

  • chainguardargo-workflows-ui-3.6

    < 3.6.19-r6

  • chainguardargo-workflows-ui-3.7

    < 3.7.13-r2

  • chainguardargo-workflows-ui-4.0

    < 4.0.4-r6

  • chainguarddrupal-11.3

    < 11.3.13-r3

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all | < 19.0.3-r1

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.1

    all | < 18.1.6-r15

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.1-r1 | < 19.1.7-r7

  • chainguardgitlab-rails-ce-fips-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-fips-19.3

    < 19.3.1-r3

  • chainguardkatib-earlystopping

    < 0.19.0-r31

  • chainguardkatib-suggestion-goptuna-compat

    all

  • chainguardkatib-suggestion-hyperband

    < 0.19.0-r31

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • chainguardkatib-suggestion-nas-darts

    < 0.19.0-r31

  • chainguardkatib-suggestion-nas-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-optuna-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-pbt-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-skopt-enas

    < 0.19.0-r31

  • chainguardkatib-tfevent-metricscollector

    < 0.19.0-r31

  • chainguardlangfuse-fips-3.152

    all

  • chainguardlangfuse-fips-3.152-worker

    all

  • chainguardlibrechat

    < 0.8.4-r5 | < 0.8.4-r3

  • chainguardopensearch-dashboards-2

    < 2.19.5-r10

  • chainguardopensearch-dashboards-2-fips

    < 2.19.5-r10

  • chainguardsqlpad

    < 7.5.7-r28

  • chainguardtileserver-gl

    < 5.5.0-r12

  • chainguardtileserver-gl-fips

    < 5.5.0-r12

Showing first 50 affected entries in server-rendered view.

References (8)