Stleary maintains the JSON-Java library, a widely embedded JSON parsing utility whose modest vulnerability footprint belies its deployment across numerous downstream applications and integrations. The recurring exposure centers on memory-safety and resource-management issues such as out-of-bounds writes and unbounded resource allocation, which reflect the parsing complexity inherent to a general-purpose serialization library. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stleary over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45688HIGH A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. | Dec 13, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-5072HIGH Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being | Oct 12, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-45690HIGH A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XM | Dec 13, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stleary.
Media articles that mention a CVE ID that affects a product developed by Stleary — matched by CVE ID, not by vendor name.