CVE-2026-37736 is a Denial of Service vulnerability affecting OWASP json-sanitizer version 1.2.3. The flaw resides in the JsonSanitizer.sanitize() method, which can be exploited by attackers through crafted input to trigger a DoS condition. The vulnerability was reported via GitHub issue tracker and is tracked in the NVD. OWASP json-sanitizer is a widely used Java library designed to sanitize JSON inputs for safe output. Exploitation does not appear to require authentication, making it accessible to remote attackers. The impact is limited to availability, with no indication of data exfiltration or code execution. Users of json-sanitizer v1.2.3 are advised to monitor for patches or mitigations from the OWASP project.