CVE-2026-30873

medium Red Hat
CVSS v3 Base Score
4.5
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Attack Characteristics
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Confidentiality
None
Integrity
None
Availability
High
Published: March 19, 2026 (55 days ago)
Last Modified: March 19, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the `jsonpath` component of the OpenWrt Project. The `jp_get_token` function, which processes input expressions, contains a memory leak vulnerability. This occurs when dynamically allocated memory used for extracting string literals, field labels, or regular expressions is not properly released after being copied to a new object. This oversight can lead to a gradual depletion of available memory, potentially resulting in a Denial of Service (DoS) for the affected system.

CWE

CWE-772

References