CVE-2023-34617
Description
Genson Java library up to version 1.6 is vulnerable to denial of service via stack overflow when deserializing crafted JSON with deeply nested structures or cyclic dependencies.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Genson Java library up to version 1.6 is vulnerable to denial of service via stack overflow when deserializing crafted JSON with deeply nested structures or cyclic dependencies.
Vulnerability
Overview The vulnerability in Genson (versions through 1.6) is a denial of service (DoS) condition caused by a stack overflow error during deserialization of specially crafted JSON input [1][2]. The root cause is that Genson does not enforce a limit on the depth of nested objects or arrays, allowing an attacker to supply a payload with excessive nesting (e.g., 9999 levels) that exhausts the call stack [2].
Exploitation
Details An attacker can exploit this by sending a JSON document with deeply nested arrays or objects to any application that uses Genson to parse untrusted JSON [2]. No authentication is required if the vulnerable endpoint is exposed publicly. The provided proof of concept demonstrates how to trigger the overflow with a nested structure of arrays [2].
Impact
Successful exploitation leads to a stack overflow crash, resulting in a denial of service for the affected service [2]. The official description also mentions possible other unspecified impacts [3].
Mitigation
Status As of the vulnerability disclosure, no patched version has been released for CVE-2023-34617; the issue remains open in the Genson repository [1][2]. Users should consider input validation, restricting nesting depth, or using an alternative JSON library until a fix is available.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.owlike:gensonMaven | <= 1.6 | — |
Affected products
2- genson/gensondescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-fj64-qprx-q7vqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-34617ghsaADVISORY
- github.com/owlike/genson/issues/191ghsaWEB
News mentions
0No linked articles in our index yet.