
🚨HIGH - go-openapi/swag jsonutils Stack Overflow DoS via Deeply Nested JSON (CVE-2026-93450) go-openapi/swag/jsonutils ordered JSON parsing/serialization uses unbounded recursion (no depth limit). Remote unauthenticated attackers can feed deeply nested JSON (e.g., OpenAPI spec payloads) to trigger a fatal stack overflow, crashing the process and dropping in-flight requests. 👉Affected: http://github.com/go-openapi/swag/jsonutils < 0.27.1 | Upgrade to 0.27.1

