GHSA-cc4v-rvgp-2pf3HighCVSS 7.5

Jawn: Uncontrolled nesting depth in JSON parser

Published
September 23, 2026
Last Modified
September 23, 2026

🔗 CVE IDs covered (1)

📋 Description

The Jawn parser before 1.6.1 is vulnerable to a denial of service attack via untrusted input.

Impact

A remote attacker who can submit JSON to any jawn-backed parse method can exhaust JVM heap and trigger java.lang.OutOfMemoryError. This is treated by Scala as a fatal error and not typically handled by scala.util.Try or cats.effect.IO.

Patches

Version 1.6.1 introduces a configurable nesting-depth limit (Parser#maxDepth, default 4096). Inputs deeper than the limit fail with a recoverable ParseException instead of exhausting heap.

Users who require deeper nesting may override maxDepth on a Parser subclass.

Workarounds

  • Enforce an input size limit small enough that the resulting context stack cannot exhaust heap, (e.g. http4s EntityLimiter).
  • Pre-scan untrusted input and reject documents whose maximum delimiter nesting exceeds a threshold before handing them to jawn.

🎯 Affected products3

  • maven/org.typelevel:jawn-parser_2.12:<= 1.6.0
  • maven/org.typelevel:jawn-parser_2.13:<= 1.6.0
  • maven/org.typelevel:jawn-parser_3:<= 1.6.0

🔗 References (7)