{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/jawn-parser--1.6.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:typelevel:jawn-parser:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-61814"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["jawn-parser (\u003c= 1.6.0)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","library-vulnerability","jvm"],"_cs_type":"advisory","_cs_vendors":["Typelevel"],"content_html":"\u003cp\u003eThe jawn-parser library contains a vulnerability (CVE-2026-61814) in its \u003ccode\u003eAsyncParser\u003c/code\u003e component that allows for a denial-of-service (DoS) attack through CPU exhaustion. When the parser processes JSON tokens delivered in small, fragmented chunks, it performs redundant rescanning of the incomplete token during each \u003ccode\u003eabsorb\u003c/code\u003e call. This quadratic complexity (O(n^2)) on the input length allows an attacker who can influence the size and delivery frequency of JSON chunks to force the application to consume excessive CPU resources. This affects users of \u003ccode\u003ejawn-parser\u003c/code\u003e versions 1.6.0 and earlier across Scala versions 2.12, 2.13, and 3. Defenders should prioritize upgrading to version 1.7.0 or switching to the synchronous \u003ccode\u003eParser\u003c/code\u003e implementation if an immediate upgrade is not feasible.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in high CPU utilization, which can lead to service degradation or complete denial of service for applications processing untrusted JSON streams. This vulnerability impacts systems utilizing \u003ccode\u003ejawn-parser\u003c/code\u003e for high-throughput or internet-facing data ingestion where attackers can control the byte-level fragmentation of incoming JSON payloads.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003ejawn-parser\u003c/code\u003e to version 1.7.0 or later to include the fix for CVE-2026-61814.\u003c/li\u003e\n\u003cli\u003eFor systems unable to upgrade, implement input buffering to ensure large chunks are provided to the \u003ccode\u003eabsorb\u003c/code\u003e method, mitigating the repeated rescanning overhead.\u003c/li\u003e\n\u003cli\u003eMigrate to the synchronous \u003ccode\u003eParser\u003c/code\u003e class for sensitive ingestion points where fragmentation control cannot be guaranteed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T01:58:04Z","date_published":"2026-09-24T01:57:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-jawn-parser-dos/","summary":"The jawn-parser library is vulnerable to a denial-of-service condition where fragmented input triggers quadratic parsing effort, leading to CPU exhaustion.","title":"Jawn AsyncParser Denial of Service via Quadratic Parsing Complexity","url":"https://feed.craftedsignal.io/briefs/2026-09-jawn-parser-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Jawn-Parser (\u003c= 1.6.0)","version":"https://jsonfeed.org/version/1.1"}