In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while parsing a single JSON document. Applications that parse attacker- controlled JSON can be forced to consume excessive CPU and memory by processing very large documents, including large arrays, objects, strings, numbers, whitespace, or nested structures, resulting in a denial of service. Eclipse Parsson 1.1.8 introduces a configurable maximum parsing limit with a default limit of 15 million parser-consumed characters.
{
"cwe_ids": [
"CWE-400",
"CWE-770"
],
"cna_assigner": "eclipse",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9563.json"
}"2026-07-15T16:34:18Z"
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 312.0,
"function_hash": "197668950211488013652816513555940810600"
},
"signature_version": "v1",
"source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
"id": "CVE-2026-9563-0136cd4b",
"target": {
"function": "read",
"file": "impl/src/main/java/org/eclipse/parsson/JsonTokenizer.java"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 695.0,
"function_hash": "327346895104216796184001749025630207580"
},
"signature_version": "v1",
"source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
"id": "CVE-2026-9563-21996f18",
"target": {
"function": "JsonContext",
"file": "impl/src/main/java/org/eclipse/parsson/JsonContext.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"327290675670993496762036182324638380338",
"283071144238102940349814463041896338769",
"112765165007102805695586456133020155265",
"191200687029865200378524373812765625730",
"140126007268959107670995941100357280287",
"134420910999188209624229215177949788480",
"145339001176091449952596283997739849481",
"139268873349650759925836238619725636699",
"291487941079730572033662507745808998250",
"11543009884402880240050379685891009931",
"187160842668853546921258497697083025494",
"284721762035327019165686160973684879845",
"176946084184458545643237246789476962061",
"93211720247560927937094064164883581622",
"37538480773397258614293393275198354884",
"20968824164253824200643927699107351665",
"104074874402172699967372783720619676875",
"90995432894566015773510587987149161312",
"327048982924789528396939789328862855787",
"19326930197733793822932988233221811808",
"18813858485546583372272021535914154069"
]
},
"signature_version": "v1",
"source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
"id": "CVE-2026-9563-3cad90cd",
"target": {
"file": "impl/src/main/java/org/eclipse/parsson/JsonTokenizer.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"110546733866479647330357442609748208210",
"39510015781670635459758707132937818268",
"88782377990093631337324973495539426382",
"232041202466062078290560274230133217717"
]
},
"signature_version": "v1",
"source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
"id": "CVE-2026-9563-6c276fe5",
"target": {
"file": "impl/src/main/java/org/eclipse/parsson/JsonMessages.java"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 649.0,
"function_hash": "172118165921378701949182573401383665575"
},
"signature_version": "v1",
"source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
"id": "CVE-2026-9563-aba82618",
"target": {
"function": "JsonContext",
"file": "impl/src/main/java/org/eclipse/parsson/JsonContext.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"263725271594754592145727599991831150733",
"207479543081002279964824483564208976299",
"203096834739151376099382620946137650193",
"127001555048200017754419375811458415658",
"198042727366855588717407342781407941039",
"150394872325862246732384587439519311105",
"9941697002779926702848340495306112958",
"105956545032620230655664641476228989165",
"163508221122953863936607160927594947695",
"80810783098920548976437072866985872571",
"289226424982306696506134053935336085061",
"121349501128736461261435512160883237435",
"163508221122953863936607160927594947695",
"80810783098920548976437072866985872571",
"289226424982306696506134053935336085061",
"197551333613961802326150268943827887617",
"204303464436780506972249928466480198512",
"70932642367377278431152620726560548782",
"116665499473885247185729199835385767243",
"18967530507823053670002185621254790880",
"169730225724998427294145938918318707613",
"136926910993687498849539873330886144575",
"112396821371201744793401518121954244846",
"108208974904138613635470648289485587458",
"86815158752971537184180725611189752404",
"18481864553970124595314221897255396116",
"247884556887205689356787728280334554561",
"10903608623400714057068745911474312235",
"177650783604101463380146554465786944497",
"156830750242815855553345947194049222251"
]
},
"signature_version": "v1",
"source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
"id": "CVE-2026-9563-be231b9e",
"target": {
"file": "impl/src/main/java/org/eclipse/parsson/JsonContext.java"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 595.0,
"function_hash": "150307001612325376024266752206132800371"
},
"signature_version": "v1",
"source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
"id": "CVE-2026-9563-c5577b41",
"target": {
"function": "readString",
"file": "impl/src/main/java/org/eclipse/parsson/JsonTokenizer.java"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 137.0,
"function_hash": "210100087185532020281803877610682996881"
},
"signature_version": "v1",
"source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
"id": "CVE-2026-9563-f024d897",
"target": {
"function": "readNumberChar",
"file": "impl/src/main/java/org/eclipse/parsson/JsonTokenizer.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"322926011778582717694913651946855556005",
"67531178784547751639064006692431765041",
"313135902199557013217673115904898461916",
"118446593566679309131201245035176533303"
]
},
"signature_version": "v1",
"source": "https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c",
"id": "CVE-2026-9563-f9ef71ba",
"target": {
"file": "impl/src/main/java/org/eclipse/parsson/api/JsonConfig.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-9563.json"