« Back to list

Typelevel

Typelevel Jawn: vulnerabilities and CVEs

Typelevel Jawn has 4 published vulnerabilities, 3 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months3
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-61814High (7.5)0.57%—Sep 23, 2026
Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered across many small chunks because each absorb call rescans the incomplete token from…
CVE-2026-59990High (7.5)0.62%—Sep 23, 2026
Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, allowing a remote attacker who can submit untrusted JSON to grow parser…
CVE-2026-66648Critical (9.8)0.48%—Aug 24, 2026
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
CVE-2022-21653High (7.5)0.79%—Jan 5, 2022
Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to a hash collision attack which may…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application3
  2. T1499.004 Application or System Exploitation2
  3. T1068 Exploitation for Privilege Escalation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Typelevel