CVE-2026-59990
- EPSS 0.62%
- Veröffentlicht 23.09.2026 18:41:12
- Zuletzt bearbeitet 30.09.2026 17:32:07
Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser contexts until the JVM heap is...
CVE-2026-61814
- EPSS 0.57%
- Veröffentlicht 23.09.2026 18:39:01
- Zuletzt bearbeitet 30.09.2026 17:32:07
Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered across many small chunks because each absorb call rescans the incomplete token from the start. A remote attacker w...
CVE-2022-21653
- EPSS 0.79%
- Veröffentlicht 05.01.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:45:09
Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to a hash collision attack which may result in a denial of service. Most...