VYPR

Parsson

by Eclipse

Source repositories

CVEs (3)

  • CVE-2023-7272HigJul 17, 2024
    risk 0.49cvss 8.6epss 0.01

    In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to cause a Java stack overflow exception and denial of service. Eclipse Parsson allows processing (e.g. parse, generate, transform and query) JSON documents.

  • CVE-2026-9563HigJul 2, 2026
    risk 0.42cvss 7.5epss 0.00

    In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while parsing a single JSON document. Applications that parse attacker- controlled JSON can be forced to consume…

  • CVE-2023-4043MedNov 3, 2023
    risk 0.31cvss 5.9epss 0.01

    In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to…