VDB

GCVE-110-NCSC-2026-307

GCVE-110-NCSC-2026-307
Advisory PublishedCVSS 9.1/10
Vulnetix · Advisory published August 19, 2026
Eclipse Parsson versions prior to 1.1.8 had a denial of service vulnerability due to the absence of a default maximum character limit during JSON parsing, which was resolved by introducing a configurable limit of 15 million characters in version 1.1.8.

Weaknesses (CWE)

CWE-770Allocation of Resources Without Limits or ThrottlingCWE-416Use After FreeCWE-476NULL Pointer DereferenceCWE-863Incorrect Authorization

Risk Scores

CVSS 3.1
9.1/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Oracle Corporationvers:unknown/*
Oraclevers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

417 records in the GCVE database · Updated August 26, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›