org.eclipse.parsson/parsson: Eclipse Parsson: Denial of Service via uncontrolled resource consumption in JSON parsing
Published Jul 2, 2026
7.5
HIGHCVSS 3.1
EPSS 0.63%
Description
In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while parsing a single JSON document. Applications that parse attacker- controlled JSON can be forced to consume excessive CPU and memory by processing very large documents, including large arrays, objects, strings, numbers, whitespace, or nested structures, resulting in a denial of service. Eclipse Parsson 1.1.8 introduces a configurable maximum parsing limit with a default limit of 15 million parser-consumed characters.
Affected products
-
- Version 1.0.0StatusaffectedConstraints<=1.1.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Eclipse Foundation | Eclipse Parsson | unaffected |
|
No data.
No data.
Red Hat OpenShift AI 2.25
rhoai/odh-trustyai-service-rhel9:1788198681
Fixed · RHSA-2026:65126
Red Hat OpenShift Dev Spaces 3.30
devspaces/openvsx-rhel9:1787759145
Fixed · RHSA-2026:62260
Red Hat OpenShift Dev Spaces 3.30
devspaces/pluginregistry-rhel9:1787759723
Fixed · RHSA-2026:62260
Cryostat 4
parsson
Not affected
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel9
Affected
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel9
Affected
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-s3-source-rhel9
Affected
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-sns-sink-rhel9
Affected
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-sqs-sink-rhel9
Affected
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-sqs-source-rhel9
Affected
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-log-sink-rhel9
Affected
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-timer-source-rhel9
Affected
Red Hat Build of Keycloak
parsson
Not affected
Red Hat Build of Keycloak
rhbk-openshift-rhel9/rhbk-openshift-rhel9
Not affected
Red Hat Build of Keycloak
rhbk-rhel9-operator/rhbk-rhel9-operator
Not affected
Red Hat Build of Keycloak
rhbk/keycloak-rhel9
Not affected
Red Hat Build of Keycloak
rhbk/keycloak-rhel9-operator
Not affected
Red Hat Data Grid 8
parsson
Not affected
Red Hat JBoss Enterprise Application Platform 8
parsson
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
parsson
Not affected
Red Hat OpenShift Dev Spaces
devspaces/multicluster-redirector-rhel9
Not affected
Red Hat build of Apache Camel - HawtIO 4
parsson
Not affected
Red Hat build of Apache Camel 4 for Quarkus 3
parsson
Not affected
Red Hat build of Apache Camel for Spring Boot 4
parsson
Not affected
Red Hat build of Apicurio Registry 3
parsson
Affected
Red Hat build of Debezium 3
parsson
Will not fix
Red Hat build of Quarkus
parsson
Not affected
streams for Apache Kafka 2
parsson
Affected
streams for Apache Kafka 3
parsson
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift AI 2.25 | rhoai/odh-trustyai-service-rhel9:1788198681 | Fixed | RHSA-2026:65126 |
| Red Hat OpenShift Dev Spaces 3.30 | devspaces/openvsx-rhel9:1787759145 | Fixed | RHSA-2026:62260 |
| Red Hat OpenShift Dev Spaces 3.30 | devspaces/pluginregistry-rhel9:1787759723 | Fixed | RHSA-2026:62260 |
| Cryostat 4 | parsson | Not affected | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel9 | Affected | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel9 | Affected | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-s3-source-rhel9 | Affected | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-sns-sink-rhel9 | Affected | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-sqs-sink-rhel9 | Affected | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-sqs-source-rhel9 | Affected | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-log-sink-rhel9 | Affected | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-timer-source-rhel9 | Affected | n/a |
| Red Hat Build of Keycloak | parsson | Not affected | n/a |
| Red Hat Build of Keycloak | rhbk-openshift-rhel9/rhbk-openshift-rhel9 | Not affected | n/a |
| Red Hat Build of Keycloak | rhbk-rhel9-operator/rhbk-rhel9-operator | Not affected | n/a |
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9 | Not affected | n/a |
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9-operator | Not affected | n/a |
| Red Hat Data Grid 8 | parsson | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | parsson | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | parsson | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/multicluster-redirector-rhel9 | Not affected | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | parsson | Not affected | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | parsson | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | parsson | Not affected | n/a |
| Red Hat build of Apicurio Registry 3 | parsson | Affected | n/a |
| Red Hat build of Debezium 3 | parsson | Will not fix | n/a |
| Red Hat build of Quarkus | parsson | Not affected | n/a |
| streams for Apache Kafka 2 | parsson | Affected | n/a |
| streams for Apache Kafka 3 | parsson | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is an Important denial of service vulnerability in Eclipse Parsson, a JSON processing library. Applications within Red Hat products that parse untrusted or attacker-controlled JSON documents are susceptible to excessive CPU and memory consumption. This can lead to resource exhaustion and service unavailability due to the parser not enforcing limits on the size or complexity of JSON input.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-9563 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2496411 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41258 Advisory
- https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c
- https://github.com/eclipse-ee4j/parsson/pull/169
- https://github.com/eclipse-ee4j/parsson/tree/1.1.8
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/444 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2026-9563
- https://repo.maven.apache.org/maven2/org/eclipse/parsson/parsson/1.1.8/
- https://www.cve.org/CVERecord?id=CVE-2026-9563
Change history (0)
No recorded changes yet.