VDB
GCVE-110-NCSC-2026-375
GCVE-110-NCSC-2026-375
Advisory PublishedCVSS 5.4/10
Eclipse Parsson versions before 1.1.8 have a denial of service vulnerability due to lack of a maximum JSON character limit, affecting multiple Oracle and Red Hat products and allowing remote attackers to cause application hangs or crashes.
Weaknesses (CWE)
CWE-770Allocation of Resources Without Limits or ThrottlingCWE-94Improper Control of Generation of Code ('Code Injection')CWE-208Observable Timing DiscrepancyCWE-787Out-of-bounds WriteCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-297Improper Validation of Certificate with Host MismatchCWE-61UNIX Symbolic Link (Symlink) FollowingCWE-1289Improper Validation of Unsafe Equivalence in InputCWE-918Server-Side Request Forgery (SSRF)CWE-116Improper Encoding or Escaping of OutputCWE-789Memory Allocation with Excessive Size ValueCWE-863Incorrect AuthorizationCWE-1284Improper Validation of Specified Quantity in InputCWE-601URL Redirection to Untrusted Site ('Open Redirect')CWE-209Generation of Error Message Containing Sensitive InformationCWE-129Improper Validation of Array IndexCWE-201Insertion of Sensitive Information Into Sent DataCWE-295Improper Certificate ValidationCWE-772Missing Release of Resource after Effective Lifetime
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Oracle | vers:unknown/* | — | — |
Aliases
CVE-2026-12590CVE-2026-13006CVE-2026-13758CVE-2026-17544CVE-2026-19880CVE-2026-34477CVE-2026-39822CVE-2026-41239CVE-2026-41989CVE-2026-44024CVE-2026-48998CVE-2026-49284CVE-2026-49844CVE-2026-50734CVE-2026-54518CVE-2026-55952CVE-2026-57220CVE-2026-58520CVE-2026-59943CVE-2026-61109CVE-2026-63308CVE-2026-64849CVE-2026-66299CVE-2026-67355CVE-2026-71290CVE-2026-73194CVE-2026-73508CVE-2026-83417CVE-2026-83418CVE-2026-83419CVE-2026-9563
References
Browse GCVE Records
406 records in the GCVE database · Updated September 17, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.