Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across trailing whitespace and then reads the source at the exhausted index without an end-of-input check. A selector ending in whitespace, including input passed through lexer.NewTokenizer(...).Tokenize() or dasel.Query, can therefore cause an index-out-of-range panic and terminate the process. This issue is fixed in version 3.11.2. | |
| Title | Dasel: Selector lexer panics on trailing whitespace in `parseCurRune` | |
| Weaknesses | CWE-129 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-21T18:00:18.178Z
Reserved: 2026-07-14T21:10:50.032Z
Link: CVE-2026-62866
No data.
Status : Received
Published: 2026-09-21T17:17:38.053
Modified: 2026-09-21T18:17:09.753
Link: CVE-2026-62866
No data.
OpenCVE Enrichment
Updated: 2026-09-21T18:30:17Z
-
CWE-129
Improper Validation of Array Index