Skip to content

[GHSA-493p-pfq6-5258] json-smart Uncontrolled Recursion vulnerability - #8697

Merged
advisory-database[bot] merged 1 commit into
oswaldobapvicjr/advisory-improvement-8697from
oswaldobapvicjr-GHSA-493p-pfq6-5258
Aug 4, 2026
Merged

[GHSA-493p-pfq6-5258] json-smart Uncontrolled Recursion vulnerability#8697
advisory-database[bot] merged 1 commit into
oswaldobapvicjr/advisory-improvement-8697from
oswaldobapvicjr-GHSA-493p-pfq6-5258

Conversation

@oswaldobapvicjr

Copy link
Copy Markdown

Updates

  • References
  • Source code location

Comments

Request: Withdraw Security Advisory (Published in Error)

Reason for Request:
This advisory (GHSA-493p-pfq6-5258) was originally published on my repository (oswaldobapvicjr/jsonmerge) by me in error, and I would like to request its withdrawal. It should have been reported under netplex/json-smart-v2 which is the correct repository as described in the Advisory details and the underlying CVE.

Technical Context:

  • The underlying vulnerability (CVE-2023-1370) belongs strictly to the third-party parser net.minidev:json-smart.
  • In oswaldobapvicjr/jsonmerge, this dependency is explicitly marked as <optional>true</optional> in the Maven POM.
  • Because jsonmerge is a provider-agnostic utility library, it does not package, bundle, or transitively force json-smart onto consuming applications.
  • Marking this as an active vulnerability of jsonmerge is causing false positives for downstream consumers who do not even pull in the affected json-smart package.

As the repository owner and the publisher of this advisory, I kindly request the GitHub Curation Team to withdraw this GHSA from my repository oswaldobapvicjr/jsonmerge

@github

github commented Jul 14, 2026

Copy link
Copy Markdown
Collaborator

Hi there @oswaldobapvicjr! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions
github-actions Bot changed the base branch from main to oswaldobapvicjr/advisory-improvement-8697 July 14, 2026 02:15
@oswaldobapvicjr

Copy link
Copy Markdown
Author

Hi GitHub Security Team!

I would appreciate it if the curation team could approve this improvement and officially withdraw/retract the global advisory to prevent further false positives for the community.

Additionally, could you please guide me on how I can completely withdraw or remove this advisory from my specific repository's Security tab as well? I currently do not see an option to delete or withdraw it from my end.

Thank you for your help!

@shelbyc

shelbyc commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Hi @oswaldobapvicjr, I removed https://github.com/oswaldobapvicjr/jsonmerge/security/advisories/GHSA-493p-pfq6-5258 from the list of reference links, because CVE-2023-1370 still legitimately affects net.minidev:json-smart but https://github.com/oswaldobapvicjr/jsonmerge shouldn't be included in discussions of CVE-2023-1370. Does that fix the issues you've experienced?

@advisory-database
advisory-database Bot merged commit bb327af into oswaldobapvicjr/advisory-improvement-8697 Aug 4, 2026
4 checks passed
@advisory-database

Copy link
Copy Markdown
Contributor

Hi @oswaldobapvicjr! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database
advisory-database Bot deleted the oswaldobapvicjr-GHSA-493p-pfq6-5258 branch August 4, 2026 22:06
@oswaldobapvicjr

Copy link
Copy Markdown
Author

Thank you, @shelbyc. I would also like to remove the advisory from my repository GHSA-493p-pfq6-5258 since it still appears there as Published. Can you guide me on how to remove it completely?

@shelbyc

shelbyc commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

@oswaldobapvicjr Per https://docs.github.com/en/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/delete-repository-advisories, you'll need to go through the GitHub support portal to have the repo advisory deleted. I'm going to show this thread to my colleagues who typically handle repo GHSA deletion requests and let them know to keep an eye out for your ticket.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants