Janino is a compact Java compiler library used for runtime code generation and expression evaluation in embedded and application contexts. Observed vulnerabilities in the project have centered on out-of-bounds write conditions, reflecting the memory-safety challenges inherent to dynamic bytecode generation and manipulation. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Janino Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33546MEDIUM Janino 3.1.9 and earlier are subject to denial of service (DOS) attacks when using the expression evaluator.guess parameter name method. If the parser runs on user-supplied input, | Jun 1, 2023 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Janino Project.
Media articles that mention a CVE ID that affects a product developed by Janino Project — matched by CVE ID, not by vendor name.