In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to cause a Java stack overflow exception and denial of service. Eclipse Parsson allows processing (e.g. parse, generate, transform and query) JSON documents.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-787"
],
"github_reviewed_at": "2024-07-17T19:29:06Z",
"nvd_published_at": "2024-07-17T15:15:10Z",
"severity": "CRITICAL"
}