Proof Portal
jsonparser
ProbeLabs23 findings · 123 requirementsThe fastest JSON parser for Go — formally verified with ReqProof (real library, master).
Set beyond-length array index on scalar array destroys all elements (SYS-REQ-110 violation)
This defect has been fixed and verified.
Introduced
When and where this issue first entered the codebase — the commit it traces back to, and the audit run that first flagged it.
Change history
Every recorded revision of this finding's source file — when it was added, edited, or re-classified, with the diff for each change.
Every recorded revision of this object's source — newest first, each with the commit message and its file-level diff.
Severity, explained
Why this is rated the way it is — and the scoring signals behind the rating (each ⓘ explains the term).
- risk area
- Data Integrity
Root cause
What actually went wrong underneath — how it is classified, and the coverage gap that let it slip through.
parser.go:Set, subpath-not-found branch: the condition guarding "append to existing array" required `data[subObjOff] == '{'`, limiting the append path to arrays whose first element is an object. All other non-empty arrays fell through to the "replace container" branch (object=true), destroying existing elements.
Disposition: Covered by a requirement
Proof it's fixed
The tests, tightened requirements and new obligations that prove this defect is gone — and can't quietly return.
Blast radius
If you touch this issue, what else may need re-checking — the requirements it affects and the code and tests that hang off them.
Nothing to trace into
This finding links no requirements, so there is no dependency graph to follow. Everything we know about it is in the evidence above.
Discussions
Discuss this with the proof team. Nothing changes in your audit automatically — you open a request and a staff member records any outcome inside the thread.