CVE-2023-5072
7.5HIGHDenial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
Published: 10/12/2023Updated: 9/19/2025
Description
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
AI AnalysisPowered by AI
Affected Products
stlearyjson-java
References
- http://www.openwall.com/lists/oss-security/2023/12/13/4
- https://github.com/stleary/JSON-java/issues/758Issue Tracking
- https://github.com/stleary/JSON-java/issues/771ExploitIssue Tracking
- https://security.netapp.com/advisory/ntap-20240621-0007/
- http://www.openwall.com/lists/oss-security/2023/12/13/4
- https://github.com/stleary/JSON-java/issues/758Issue Tracking
- https://github.com/stleary/JSON-java/issues/771ExploitIssue Tracking
- https://security.netapp.com/advisory/ntap-20240621-0007/