Typelevel
Typelevel Jawn: vulnerabilities and CVEs
Typelevel Jawn has 4 published vulnerabilities, 3 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months3
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61814 | High (7.5) | 0.57% | — | Sep 23, 2026 | Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered across many small chunks because each absorb call rescans the incomplete token from… |
| CVE-2026-59990 | High (7.5) | 0.62% | — | Sep 23, 2026 | Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser… |
| CVE-2026-66648 | Critical (9.8) | 0.48% | — | Aug 24, 2026 | Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions. |
| CVE-2022-21653 | High (7.5) | 0.79% | — | Jan 5, 2022 | Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to a hash collision attack which may… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.