SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-37736

HIGH · CVSS 7.5 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The JsonSanitizer.sanitize() component in OWASP json-sanitizer v1.2.3 is vulnerable to a Denial of Service (DoS) attack when processing specially crafted input. This vulnerability could lead to service interruptions for applications utilizing this library. Organizations using this version of json-sanitizer should prioritize remediation to prevent potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-37736
Severity
HIGH
CVSS
7.5
EPSS
0.34%

Original NVD Description

An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.