GHSA-w4cm-gvhj-cgw6HighCVSS 7.5
Jawn: Quadratic parsing effort in AsyncParser
🔗 CVE IDs covered (1)
📋 Description
AsyncParser can be forced to perform O(n^2) work on the length of the input. When a single JSON token arrives across many small chunks, each absorb call rescans the incomplete token from the start.
Impact
Denial of service via CPU exhaustion when parsing untrusted JSON.
Preconditions:
- Application uses
AsyncParser - Attacker can send large tokens with control over chunk sizes.
Patches
Fixed in jawn-parser-1.7.0.
Workarounds
If you can't upgrade immediately:
- Use the synchronous
Parser. - Buffer incoming bytes into larger chunks before calling
absorb
🎯 Affected products3
- maven/org.typelevel:jawn-parser_2.12:<= 1.6.0
- maven/org.typelevel:jawn-parser_2.13:<= 1.6.0
- maven/org.typelevel:jawn-parser_3:<= 1.6.0