Medium severity5.5NVD Advisory· Published Jun 1, 2023· Updated Jun 17, 2026
CVE-2023-33546
CVE-2023-33546
Description
Janino 3.1.9 and earlier are subject to denial of service (DOS) attacks when using the expression evaluator.guess parameter name method. If the parser runs on user-supplied input, an attacker could supply content that causes the parser to crash due to a stack overflow. NOTE: this is disputed by multiple parties because Janino is not intended for use with untrusted input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.codehaus.janino:janino-parentMaven | <= 3.1.9 | — |
Affected products
5- Janino/Janinodescription
- ghsa-coords3 versionspkg:maven/org.codehaus.janino/janino-parentpkg:rpm/opensuse/janino&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/janino&distro=openSUSE%20Leap%2015.5
<= 3.1.9+ 2 more
- (no CPE)range: <= 3.1.9
- (no CPE)range: < 3.1.10-150200.3.7.1
- (no CPE)range: < 3.1.10-150200.3.7.1
Patches
Vulnerability mechanics
References
4- github.com/janino-compiler/janino/issues/201nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-gcg6-xv4f-f749ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-33546ghsaADVISORY
- janino-compiler.github.io/janino/nvdWEB
News mentions
0No linked articles in our index yet.