Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223832 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-9563
eclip · parsson

CVE-2026-9563: In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default max

Description

In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while parsing a single JSON document. Applications that parse attacker- controlled JSON can be forced to consume excessive CPU and memory by processing very large documents, including large arrays, objects, strings, numbers, whitespace, or nested structures, resulting in a denial of service. Eclipse Parsson 1.1.8 introduces a configurable maximum parsing limit with a default limit of 15 million parser-consumed characters.

Affected Products

VendorProductVersions
eclipparsson1.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmwebsphere application server libertycert_advisory90%
oraclecommunicationscert_advisory90%

References

  • https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c
  • https://github.com/eclipse-ee4j/parsson/pull/169
  • https://repo.maven.apache.org/maven2/org/eclipse/parsson/parsson/1.1.8/
  • https://github.com/eclipse-ee4j/parsson/tree/1.1.8
  • https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/444

Related News (7 articles)

Tier B
CERT-FR3d ago
Multiples vulnérabilités dans les produits IBM (25 septembre 2026)
→ No new info (linked only)
Tier B
BSI Advisories11d ago
[NEU] [hoch] Oracle Communications: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits IBM (11 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR31d ago
Multiples vulnérabilités dans les produits IBM (28 août 2026)
→ No new info (linked only)
Tier B
CERT-FR45d ago
Multiples vulnérabilités dans les produits IBM (14 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories81d ago
[NEU] [mittel] IBM WebSphere Application Server Liberty: Schwachstelle ermöglicht Denial of Service
→ No new info (linked only)
Tier C
VulDB87d ago
CVE-2026-9563 | Eclipse Parsson up to 1.1.7 JSON Parser resource consumption
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-400, CWE-770
PublishedJul 2, 2026
Last enriched87d agov2
Trending Score43
Source articles7
Independent3
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-10050
Digest authentication lossy encoding
Trending: 20
MEDIUMCVE-2026-6790EXP
CVE-2026-6790: In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and
Trending: 15
MEDIUMCVE-2026-10051EXP
CVE-2026-10051: In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests
Trending: 15
MEDIUMCVE-2026-8384EXP
CVE-2026-8384: In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of:
Trending: 6
HIGHCVE-2026-14336EXP
CVE-2026-14336: PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.o

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 2, 2026
Discovered by ZDM
Jul 2, 2026
Updated: affectedVersions
Jul 2, 2026

Version History

v2
Last enriched 87d ago
v2Tier C87d ago

Updated affected versions to include 1.1.7 and confirmed no available exploit.

affectedVersions
via VulDB
v187d ago

Initial creation