github.com/ipld/go-ipld-prime
Golang interfaces for the IPLD Data Model, with core Codecs included, IPLD Schemas support, and some handy functional transforms tools.
Activity
- Latest release
- 3mo ago
- Total releases
- 29
- Cadence
- ~2 months
- Last 12 months
- 3
Reach
- Stars
- 151
Details
- First release
- Aug 08, 2019
| Version | Released | |
|---|---|---|
v0.24.0
minor
|
v0.24.0
minor
Dependencies (8)
|
|
v0.23.0
minor
|
v0.23.0
minor
Dependencies (8)
|
|
v0.22.0
minor
1 CVE
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v0.22.0
minor
Dependencies (8)
|
|
v0.21.0
minor
2 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.21.0
minor
Dependencies (8)
|
|
v0.20.0
minor
2 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.20.0
minor
Dependencies (8)
|
|
v0.19.0
minor
2 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.19.0
minor
Dependencies (8)
|
|
v0.18.0
minor
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.18.0
minor
Dependencies (8)
|
|
v0.17.0
minor
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.17.0
minor
Dependencies (8)
|
|
v0.16.0
minor
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.16.0
minor
Dependencies (8)
|
|
v0.14.4
patch
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.14.4
patch
Dependencies (8)
|
|
v0.14.3
patch
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.14.3
patch
Dependencies (8)
|
|
v0.14.2
patch
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.14.2
patch
Dependencies (8)
|
|
v0.14.1
patch
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.14.1
patch
Dependencies (8)
|
|
v0.14.0
minor
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.14.0
minor
Dependencies (9)
+ 1 more |
|
v0.12.3
patch
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.12.3
patch
Dependencies (7)
|
|
v0.12.2
patch
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.12.2
patch
Dependencies (7)
|
|
v0.12.1
patch
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.12.1
patch
Dependencies (6)
|
|
v0.12.0
minor
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.12.0
minor
Dependencies (6)
|
|
v0.11.0
minor
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.11.0
minor
Dependencies (5)
|
|
v0.10.0
minor
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.10.0
minor
Dependencies (5)
|
|
v0.9.0
minor
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.9.0
minor
Dependencies (5)
|
|
v0.7.0
minor
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.7.0
minor
Dependencies (3)
|
|
v0.6.0
minor
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.6.0
minor
Dependencies (3)
|
|
v0.5.0
minor
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.5.0
minor
Dependencies (3)
|
|
v0.4.0
minor
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.4.0
minor
Dependencies (3)
|
|
v0.0.3
patch
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.3
patch
Dependencies (3)
|
|
v0.0.2
patch
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.2
patch
Dependencies (3)
|
|
v0.0.1-filecoin
pre
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.1-filecoin
pre
Dependencies (3)
|
|
v0.0.1
initial
3 CVEs
CVE-2026-42328
GO-2026-5684
GHSA-w239-58x2-q8p5
Jul 24, 2026
Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth in github.com/ipld/go-ipld-prime Fixed in
0.23.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35480
GO-2026-5073
GHSA-378j-3jfj-8r9f
Jul 07, 2026
DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime DAG-CBOR decoder unbounded memory allocation from CBOR headers in github.com/ipld/go-ipld-prime Fixed in
0.22.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-22460
GO-2023-1269
GHSA-c653-6hhg-9x92
Jan 18, 2023
Panic in encoding in github.com/ipld/go-ipld-prime Encoding data using the 'json' codec which contains a 'Bytes' type Node will cause the encoder to panic. The decoder is not impacted. If the codec is used to encode user supplied data, this may be used as a vector for a denial of service attack. Fixed in
0.19.0
References Updated May 20, 2024 · Source: OSV.dev |
v0.0.1
initial
Dependencies (3)
|