High severity7.5NVD Advisory· Published Nov 6, 2020· Updated Jun 17, 2026
CVE-2020-27196
CVE-2020-27196
Description
An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly parses a payload given a Content-Type header. A deep JSON structure sent to a valid POST endpoint (that may or may not expect JSON payloads) causes a StackOverflowError and Denial of Service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.typesafe.play:playMaven | >= 2.6.0, < 2.7.6 | 2.7.6 |
com.typesafe.play:playMaven | >= 2.8.0, < 2.8.3 | 2.8.3 |
com.typesafe.play:play-javaMaven | >= 2.6.0, < 2.7.6 | 2.7.6 |
com.typesafe.play:play-javaMaven | >= 2.8.0, < 2.8.3 | 2.8.3 |
Affected products
4- PlayJava/Play Frameworkdescription
- ghsa-coords2 versions
>= 2.6.0, < 2.7.6+ 1 more
- (no CPE)range: >= 2.6.0, < 2.7.6
- (no CPE)range: >= 2.6.0, < 2.7.6
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-h48w-c35p-6m8xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-27196ghsaADVISORY
- www.playframework.com/security/vulnerabilitynvdVendor Advisory
- www.playframework.com/security/vulnerability/CVE-2020-27196-DosViaJsonStackOverflownvdVendor AdvisoryWEB
- github.com/playframework/playframework/pull/10321ghsaWEB
News mentions
0No linked articles in our index yet.