VYPR
Medium severity5.9NVD Advisory· Published Nov 3, 2023· Updated Jun 17, 2026

CVE-2023-4043

CVE-2023-4043

Description

In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect.

To mitigate the risk, parsson put in place a size limit for the numbers as well as their scale.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.eclipse.parsson:projectMaven
>= 1.1.0, < 1.1.41.1.4
org.eclipse.parsson:projectMaven
< 1.0.51.0.5

Affected products

3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.