CVE-2026-9563

Source
https://cve.org/CVERecord?id=CVE-2026-9563
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9563.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-9563
Downstream
Published
2026-07-02T07:33:25.218Z
Modified
2026-07-15T16:34:18.117578Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while parsing a single JSON document. Applications that parse attacker- controlled JSON can be forced to consume excessive CPU and memory by processing very large documents, including large arrays, objects, strings, numbers, whitespace, or nested structures, resulting in a denial of service. Eclipse Parsson 1.1.8 introduces a configurable maximum parsing limit with a default limit of 15 million parser-consumed characters.

Database specific
{
    "cwe_ids": [
        "CWE-400",
        "CWE-770"
    ],
    "cna_assigner": "eclipse",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9563.json"
}
References

Affected packages

Git / github.com/eclipse-ee4j/parsson

Affected ranges

Type
GIT
Repo
https://github.com/eclipse-ee4j/parsson
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.1.8"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Database specific

vanir_signatures_modified
"2026-07-15T16:34:18Z"
vanir_signatures
[
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 312.0,
            "function_hash": "197668950211488013652816513555940810600"
        },
        "signature_version": "v1",
        "source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
        "id": "CVE-2026-9563-0136cd4b",
        "target": {
            "function": "read",
            "file": "impl/src/main/java/org/eclipse/parsson/JsonTokenizer.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 695.0,
            "function_hash": "327346895104216796184001749025630207580"
        },
        "signature_version": "v1",
        "source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
        "id": "CVE-2026-9563-21996f18",
        "target": {
            "function": "JsonContext",
            "file": "impl/src/main/java/org/eclipse/parsson/JsonContext.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "327290675670993496762036182324638380338",
                "283071144238102940349814463041896338769",
                "112765165007102805695586456133020155265",
                "191200687029865200378524373812765625730",
                "140126007268959107670995941100357280287",
                "134420910999188209624229215177949788480",
                "145339001176091449952596283997739849481",
                "139268873349650759925836238619725636699",
                "291487941079730572033662507745808998250",
                "11543009884402880240050379685891009931",
                "187160842668853546921258497697083025494",
                "284721762035327019165686160973684879845",
                "176946084184458545643237246789476962061",
                "93211720247560927937094064164883581622",
                "37538480773397258614293393275198354884",
                "20968824164253824200643927699107351665",
                "104074874402172699967372783720619676875",
                "90995432894566015773510587987149161312",
                "327048982924789528396939789328862855787",
                "19326930197733793822932988233221811808",
                "18813858485546583372272021535914154069"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
        "id": "CVE-2026-9563-3cad90cd",
        "target": {
            "file": "impl/src/main/java/org/eclipse/parsson/JsonTokenizer.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "110546733866479647330357442609748208210",
                "39510015781670635459758707132937818268",
                "88782377990093631337324973495539426382",
                "232041202466062078290560274230133217717"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
        "id": "CVE-2026-9563-6c276fe5",
        "target": {
            "file": "impl/src/main/java/org/eclipse/parsson/JsonMessages.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 649.0,
            "function_hash": "172118165921378701949182573401383665575"
        },
        "signature_version": "v1",
        "source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
        "id": "CVE-2026-9563-aba82618",
        "target": {
            "function": "JsonContext",
            "file": "impl/src/main/java/org/eclipse/parsson/JsonContext.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "263725271594754592145727599991831150733",
                "207479543081002279964824483564208976299",
                "203096834739151376099382620946137650193",
                "127001555048200017754419375811458415658",
                "198042727366855588717407342781407941039",
                "150394872325862246732384587439519311105",
                "9941697002779926702848340495306112958",
                "105956545032620230655664641476228989165",
                "163508221122953863936607160927594947695",
                "80810783098920548976437072866985872571",
                "289226424982306696506134053935336085061",
                "121349501128736461261435512160883237435",
                "163508221122953863936607160927594947695",
                "80810783098920548976437072866985872571",
                "289226424982306696506134053935336085061",
                "197551333613961802326150268943827887617",
                "204303464436780506972249928466480198512",
                "70932642367377278431152620726560548782",
                "116665499473885247185729199835385767243",
                "18967530507823053670002185621254790880",
                "169730225724998427294145938918318707613",
                "136926910993687498849539873330886144575",
                "112396821371201744793401518121954244846",
                "108208974904138613635470648289485587458",
                "86815158752971537184180725611189752404",
                "18481864553970124595314221897255396116",
                "247884556887205689356787728280334554561",
                "10903608623400714057068745911474312235",
                "177650783604101463380146554465786944497",
                "156830750242815855553345947194049222251"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
        "id": "CVE-2026-9563-be231b9e",
        "target": {
            "file": "impl/src/main/java/org/eclipse/parsson/JsonContext.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 595.0,
            "function_hash": "150307001612325376024266752206132800371"
        },
        "signature_version": "v1",
        "source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
        "id": "CVE-2026-9563-c5577b41",
        "target": {
            "function": "readString",
            "file": "impl/src/main/java/org/eclipse/parsson/JsonTokenizer.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 137.0,
            "function_hash": "210100087185532020281803877610682996881"
        },
        "signature_version": "v1",
        "source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
        "id": "CVE-2026-9563-f024d897",
        "target": {
            "function": "readNumberChar",
            "file": "impl/src/main/java/org/eclipse/parsson/JsonTokenizer.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "322926011778582717694913651946855556005",
                "67531178784547751639064006692431765041",
                "313135902199557013217673115904898461916",
                "118446593566679309131201245035176533303"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
        "id": "CVE-2026-9563-f9ef71ba",
        "target": {
            "file": "impl/src/main/java/org/eclipse/parsson/api/JsonConfig.java"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9563.json"