VYPR

jawn

by Typelevel

Source repositories

CVEs (3)

  • CVE-2026-61814HigSep 23, 2026
    risk 0.42cvss 7.5epss 0.01

    Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered across many small chunks because each absorb call rescans the incomplete token from the start. A remote attacker who controls untrusted JSON…

  • CVE-2026-59990HigSep 23, 2026
    risk 0.42cvss 7.5epss 0.01

    Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser contexts until the JVM heap is exhausted. The resulting…

  • CVE-2022-21653MedJan 5, 2022
    risk 0.00cvss 5.9epss 0.01

    Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not…