Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-1370

23
FAUCET Score

CVE-2023-1370 is a stack exhaustion vulnerability affecting the json-smart library, a performance-focused JSON processor. The flaw arises from unbounded recursion when parsing deeply nested JSON arrays or objects, leading to a denial-of-service condition. It carries a CVSS score of 7.5 (High) due to its network-based attack vector, low complexity, and high impact on availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.4.9CPE matchmatch criteria
cpe:2.3:a:json-smart_project:json-smart:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.12%
Probability of exploitation in next 30 days
EPSS Percentile
62.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0112 is in the 41st percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (26)

mavenpatch availablevia ghsa
Product: net.minidev:json-smartFixed in: 2.4.9
nodejspatch availablevia llm_extracted
Fixed in: 25.4.0
redhatpatch availablevia redhat_api
Product: AMQ ClientsFixed in: json-smart
View patch
redhatpatch availablevia redhat_api
Product: CEQ 2.7.1-1Fixed in: json-smart
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.12-RHEL-8Fixed in: jenkins-2-plugins-0:4.12.1686649756-1.el8
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.13-RHEL-8Fixed in: jenkins-0:2.401.1.1686680404-3.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Developer Tools and Services for OCP 4.11Fixed in: jenkins-2-plugins-0:4.11.1686831822-1.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 2.4.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 2.7.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.12Fixed in: json-smart
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.10Fixed in: jenkins-2-plugins-0:4.10.1684982411-1.el8
View patch
redhatpatch availablevia redhat_api
Product: RHINT Camel-K-1.10.1Fixed in: json-smart
View patch
redhatpatch availablevia redhat_api
Product: RHINT Camel-Springboot 3.18.3.P1Fixed in: json-smart
View patch
redhatpatch availablevia redhat_api
Product: RHINT Camel-Springboot 3.18.3.P2Fixed in: json-smart
View patch
redhatpatch availablevia redhat_api
Product: RHINT Camel-Springboot 3.20.1Fixed in: json-smart
View patch
redhatpatch availablevia redhat_api
Product: Streams for Apache Kafka 2.9.1
View patch
redhatpatch availablevia redhat_api
Product: Streams for Apache Kafka 3.0.0
View patch
redhatpatch availablevia redhat_api
Product: CEQ 2.13.2-2Fixed in: json-smart
View patch
redhatno patchvia redhat_api
Product: Red Hat AMQ Broker 7Fixed in: json-smart
redhatno patchvia redhat_api
Product: Red Hat build of Debezium 1Fixed in: json-smart
redhatno patchvia redhat_api
Product: Red Hat Data Grid 8Fixed in: json-smart
redhatno patchvia redhat_api
Product: Red Hat OpenShift Application RuntimesFixed in: json-smart
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/pluginregistry-rhel8
redhatno patchvia redhat_api
Product: Red Hat Process Automation 7Fixed in: json-smart
redhatno patchvia redhat_api
Product: streams for Apache KafkaFixed in: json-smart
redhatno patchvia redhat_api
Product: A-MQ Clients 2Fixed in: json-smart

Vendor Advisories (3)

nodejsllm-nodejs-9e1762a1939f642dCRITICAL

Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025

Aug 6, 2025
mavenGHSA-493p-pfq6-5258high

json-smart Uncontrolled Recursion vulnerability

Mar 23, 2023
redhatCVE-2023-1370Important

json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion)

Mar 22, 2023

References

research.jfrog.com / vulnerabilities/stack-exhaustion-in-json-smart-leads-to-denial-of-service-when-parsing-malformed-json-xray-427633
ExploitThird Party Advisory
security.netapp.com / advisory/ntap-20240621-0006