Intel

AIKIDO-2025-10521

github.com/samber/oops is vulnerable to Undefined Behavior

Undefined Behavior Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

18

Low Risk

This Affects:

GOgithub.com/samber/oops
1.0.0 - 1.18.1
Fixed in 1.19.0

TL;DR

Affected versions of this package are vulnerable to a panic triggered by dereferencing excessively nested pointers. An attacker can exploit this by providing crafted input that causes the application to exceed the call stack or memory limits, potentially leading to a denial of service.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges.

Background info

github.com/samber/oops is vulnerable to Undefined Behavior in versions 1.0.0 - 1.18.1.

How to fix this

Upgrade the github.com/samber/oops library to the patch version.