org.typelevel:jawn-parser_3
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.typelevel:jawn-parser_3page 1 of 1
- CVE-2022-21653MEDIUMCVSS 5.9EG 5.9fixed in 1.3.22022-01-05
vulnerable: 1.1.2, 1.2.0, 1.3.0, 1.3.1
Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to a hash collision attack which may result in a denial of se…
- CVE-2026-59990HIGHCVSS 7.5EG 7.5fixed in 1.7.02026-09-23
vulnerable: 1.1.2 ... 1.6.0 (9 versions)
Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser contexts until the …
- CVE-2026-61814HIGHCVSS 7.5EG 7.5fixed in 1.7.02026-09-23
vulnerable: 1.1.2 ... 1.6.0 (9 versions)
Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered across many small chunks because each absorb call rescans the incomplete token from the start. A remote…
Check whether org.typelevel:jawn-parser_3 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.typelevel:jawn-parser_3 CVEs against the assets you own.
Book a Demo →