๐Ÿ” CVE Alert

CVE-2026-59990

HIGH 7.5

Jawn: Uncontrolled nesting depth in JSON parser

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser contexts until the JVM heap is exhausted. The resulting java.lang.OutOfMemoryError is a fatal Scala error that is not ordinarily handled by scala.util.Try or cats.effect.IO, causing denial of service. This issue is fixed in version 1.7.0.

CWE CWE-770
Vendor typelevel
Product jawn
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for typelevel jawn

Be the first to know when new high vulnerabilities affecting typelevel jawn are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

typelevel / jawn
< 1.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/typelevel/jawn/security/advisories/GHSA-cc4v-rvgp-2pf3 github.com: https://github.com/typelevel/jawn/commit/191cb3a44e77f1afab439ee636bf66bdf3c54a04 github.com: https://github.com/typelevel/jawn/commit/6219666641f9408498f85868f835e17bd8a72fed github.com: https://github.com/typelevel/jawn/commit/93ac93e9c992c11b4c03d5455d8551f9fb24da1b github.com: https://github.com/typelevel/jawn/commit/f6ace7e0db715de1a8c4618bed9378333a5c2214 github.com: https://github.com/typelevel/jawn/releases/tag/v1.7.0