8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/tomwright/dasel/v3 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.2
CVE-2026-59168
Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS
MEDIUM 6.2
CVE-2026-62866
Dasel: Selector lexer panics on trailing whitespace in `parseCurRune`
HIGH 7.5
CVE-2026-46378
Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
HIGH 7.5
CVE-2026-46377
Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
MEDIUM 6.2
CVE-2026-33320
Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service
UNKNOWN
CVE-2026-46378
Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal in github.com/tomwright/dasel
UNKNOWN
CVE-2026-46377
Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string in github.com/tomwright/dasel
UNKNOWN
CVE-2026-33320
Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service in github.com/tomwright/dasel
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes