VDB
GCVE-110-NCSC-2026-307
GCVE-110-NCSC-2026-307
Advisory PublishedCVSS 9.1/10
Eclipse Parsson versions prior to 1.1.8 had a denial of service vulnerability due to the absence of a default maximum character limit during JSON parsing, which was resolved by introducing a configurable limit of 15 million characters in version 1.1.8.
Weaknesses (CWE)
CWE-770Allocation of Resources Without Limits or ThrottlingCWE-416Use After FreeCWE-476NULL Pointer DereferenceCWE-863Incorrect Authorization
Risk Scores
CVSS 3.1
9.1/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Oracle Corporation | vers:unknown/* | — | — |
| Oracle | vers:unknown/* | — | — |
Aliases
CVE-2026-29167CVE-2026-42764CVE-2026-45447CVE-2026-59889CVE-2026-70688CVE-2026-70689CVE-2026-70715CVE-2026-70717CVE-2026-70728CVE-2026-70731CVE-2026-70734CVE-2026-70862CVE-2026-70863CVE-2026-70864CVE-2026-70865CVE-2026-70866CVE-2026-70867CVE-2026-70868CVE-2026-71062CVE-2026-71063CVE-2026-71064CVE-2026-71100CVE-2026-71102CVE-2026-9563
Browse GCVE Records
417 records in the GCVE database · Updated August 26, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.