CVE-2023-1436: Jettison Project Jettison
High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.
An infinite recursion is triggered in Jettison when constructing a JSONArray from a Collection that contains a self-reference in one of its elements. This leads to a StackOverflowError exception being thrown.
Affected products
- Jettison Project Jettison: before 1.5.4 (fixed in 1.5.4)
Published 2023-03-22. Last modified 2026-06-17.