CVE-2023-7272: Eclipse Parsson

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to cause a Java stack overflow exception and denial of service. Eclipse Parsson allows processing (e.g. parse, generate, transform and query) JSON documents.

Affected products

  • Eclipse Parsson: before 1.0.4 (fixed in 1.0.4); from 1.1.0, before 1.1.3 (fixed in 1.1.3)

Published 2024-07-17. Last modified 2026-06-17.