The number and severity of CVEs published that impact products developed by Jmespath over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54133CRITICAL jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Version | Jun 12, 2026 | 9.8 | 37 | NO | NO |
CVE-2022-32511CRITICAL jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. | Jun 6, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jmespath.
Media articles that mention a CVE ID that affects a product developed by Jmespath — matched by CVE ID, not by vendor name.