mediumCVSS 5.3Vulnerability

GHSA-86rf-68f4-2cph

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-2464-8j7c-4cjm. This link is maintained to preserve external references. ### Original Description A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data processed in security-critical contexts.

Properties

ghsa_id
GHSA-86rf-68f4-2cph
severity
medium
summary
Duplicate Advisory: go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data
cvss_score
5.3
cve_id
GHSA-86rf-68f4-2cph
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-01-26T21:30:36Z
source_url
https://github.com/advisories/GHSA-86rf-68f4-2cph
ghsa_updated
2026-01-27T21:00:34Z

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Improper Output Neutralization for Logs

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]go/github.com/go-viper/mapstructure/v2

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-86rf-68f4-2cph (CVSS 5.3) — Ninja Signal Threat Intelligence | Ninja Signal