{"schema_version":"1.9.0","id":"CVE-2022-28946","published":"2022-05-19T18:03:47Z","modified":"2026-08-12T03:51:35.464981209Z","aliases":["GHSA-x7f3-62pm-9p38","GO-2022-0587"],"related":["CGA-hhxp-vvgj-pr2v","openSUSE-SU-2022:10022-1","openSUSE-SU-2022:10094-1","openSUSE-SU-2024:12102-1","openSUSE-SU-2024:12128-1"],"details":"An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open-policy-agent/opa","events":[{"introduced":"cc965f633e3769de51f7e92f8caf40ba0328ab1d"},{"fixed":"e9d3828db670cbe11129885f37f08cbf04935264"}],"database_specific":{"cpe":"cpe:2.3:a:openpolicyagent:open_policy_agent:0.39.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.39.0"},{"last_affected":"0.39.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.39.0","v0.39.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-28946.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28946.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28946"},{"type":"FIX","url":"https://github.com/open-policy-agent/opa/commit/e9d3828db670cbe11129885f37f08cbf04935264"}],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28946.json"}}