7.5
CVE-2026-59990
- EPSS 0.62%
- Veröffentlicht 23.09.2026 18:41:12
- Zuletzt bearbeitet 30.09.2026 17:32:07
- Erkennungen
Jawn: Uncontrolled nesting depth in JSON parser
Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser contexts until the JVM heap is exhausted. The resulting java.lang.OutOfMemoryError is a fatal Scala error that is not ordinarily handled by scala.util.Try or cats.effect.IO, causing denial of service. This issue is fixed in version 1.7.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellertypelevel
≫
Produkt
jawn
Version
< 1.7.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.62% | 0.476 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
https://github.com/typelevel/jawn/security/advisories/GHSA-cc4v-rvgp-2pf3
https://github.com/typelevel/jawn/commit/191cb3a44e77f1afab439ee636bf66bdf3c54a04
https://github.com/typelevel/jawn/commit/6219666641f9408498f85868f835e17bd8a72fed
https://github.com/typelevel/jawn/commit/93ac93e9c992c11b4c03d5455d8551f9fb24da1b
https://github.com/typelevel/jawn/commit/f6ace7e0db715de1a8c4618bed9378333a5c2214
https://github.com/typelevel/jawn/releases/tag/v1.7.0