High severity7.5NVD Advisory· Published Nov 6, 2020· Updated Jun 17, 2026
CVE-2020-26883
CVE-2020-26883
Description
In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.typesafe.play:playMaven | >= 2.6.0, < 2.7.6 | 2.7.6 |
com.typesafe.play:playMaven | >= 2.8.0, < 2.8.3 | 2.8.3 |
com.typesafe.play:play-javaMaven | >= 2.6.0, < 2.7.6 | 2.7.6 |
com.typesafe.play:play-javaMaven | >= 2.8.0, < 2.8.3 | 2.8.3 |
Affected products
4- Play Framework/Play Frameworkdescription
- ghsa-coords2 versions
>= 2.6.0, < 2.7.6+ 1 more
- (no CPE)range: >= 2.6.0, < 2.7.6
- (no CPE)range: >= 2.6.0, < 2.7.6
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-p8p6-rcp6-4mrmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-26883ghsaADVISORY
- www.playframework.com/security/vulnerabilitynvdVendor Advisory
- www.playframework.com/security/vulnerability/CVE-2020-26883-JsonParseUncontrolledRecursionnvdVendor AdvisoryWEB
- github.com/playframework/playframework/pull/10495ghsaWEB
News mentions
0No linked articles in our index yet.