GHSA-w4cm-gvhj-cgw6HighCVSS 7.5

Jawn: Quadratic parsing effort in AsyncParser

Published
September 23, 2026
Last Modified
September 23, 2026

🔗 CVE IDs covered (1)

📋 Description

AsyncParser can be forced to perform O(n^2) work on the length of the input. When a single JSON token arrives across many small chunks, each absorb call rescans the incomplete token from the start.

Impact

Denial of service via CPU exhaustion when parsing untrusted JSON.

Preconditions:

  • Application uses AsyncParser
  • Attacker can send large tokens with control over chunk sizes.

Patches

Fixed in jawn-parser-1.7.0.

Workarounds

If you can't upgrade immediately:

  • Use the synchronous Parser.
  • Buffer incoming bytes into larger chunks before calling absorb

🎯 Affected products3

  • maven/org.typelevel:jawn-parser_2.12:<= 1.6.0
  • maven/org.typelevel:jawn-parser_2.13:<= 1.6.0
  • maven/org.typelevel:jawn-parser_3:<= 1.6.0

🔗 References (4)