{"id":"CVE-2026-59990","title":"Jawn is an open source JSON parser","summary":"Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser contexts until th…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-770"],"vendor":"typelevel","product":"jawn","affected":["jawn < 1.7.0"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T20:17:11.903","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59990","references":[{"url":"https://github.com/typelevel/jawn/commit/191cb3a44e77f1afab439ee636bf66bdf3c54a04","label":"security-advisories@github.com"},{"url":"https://github.com/typelevel/jawn/commit/6219666641f9408498f85868f835e17bd8a72fed","label":"security-advisories@github.com"},{"url":"https://github.com/typelevel/jawn/commit/93ac93e9c992c11b4c03d5455d8551f9fb24da1b","label":"security-advisories@github.com"},{"url":"https://github.com/typelevel/jawn/commit/f6ace7e0db715de1a8c4618bed9378333a5c2214","label":"security-advisories@github.com"},{"url":"https://github.com/typelevel/jawn/releases/tag/v1.7.0","label":"security-advisories@github.com"},{"url":"https://github.com/typelevel/jawn/security/advisories/GHSA-cc4v-rvgp-2pf3","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-cc4v-rvgp-2pf3"}],"tags":["nvd","cve.org","ghsa","maven"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-23T19:27:50.740766Z"},"ingestedAt":"2026-09-23T19:31:04.461Z","aliases":["GHSA-cc4v-rvgp-2pf3"],"ecosystem":"maven","patched":["org.typelevel:jawn-parser_2.12 1.7.0","org.typelevel:jawn-parser_2.13 1.7.0","org.typelevel:jawn-parser_3 1.7.0"],"slug":"CVE-2026-59990","body":"## Overview\n\nJawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser contexts until the JVM heap is exhausted. The resulting java.lang.OutOfMemoryError is a fatal Scala error that is not ordinarily handled by scala.util.Try or cats.effect.IO, causing denial of service. This issue is fixed in version 1.7.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-59990)\n\nAffected packages:\n\n- `org.typelevel:jawn-parser_2.12 <= 1.6.0`\n- `org.typelevel:jawn-parser_2.13 <= 1.6.0`\n- `org.typelevel:jawn-parser_3 <= 1.6.0`\n\nPatched in:\n\n- `org.typelevel:jawn-parser_2.12 1.7.0`\n- `org.typelevel:jawn-parser_2.13 1.7.0`\n- `org.typelevel:jawn-parser_3 1.7.0`\n\nSource: https://github.com/advisories/GHSA-cc4v-rvgp-2pf3","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}