The Jettison Project maintains a lightweight JSON serialization library that, despite its narrow product scope, sees broad adoption across Java applications and frameworks where compact data interchange is needed. Its vulnerability profile centers on memory-safety and resource-handling weaknesses including out-of-bounds writes, stack-based buffer overflows, uncontrolled recursion, and uncontrolled resource consumption—issues typical of parsing-layer code exposed to untrusted input. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jettison Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40150HIGH Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supp | Sep 16, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-45693HIGH Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string | Dec 13, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-45685HIGH A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data. | Dec 13, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-1436HIGH An infinite recursion is triggered in Jettison when constructing a JSONArray from a Collection that contains a self-reference in one of its elements. This leads to a StackOverflowE | Mar 22, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-40149HIGH Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supp | Sep 16, 2022 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jettison Project.
Media articles that mention a CVE ID that affects a product developed by Jettison Project — matched by CVE ID, not by vendor name.