<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:34:42.982768+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232849</id>
    <title>EUVD-2026-232849</title>
    <updated>2026-10-03T21:34:43.090106+00:00</updated>
    <content>EUVD-2026-232849</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232849"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21653</id>
    <title>fkie_cve-2022-21653</title>
    <updated>2026-10-03T21:34:43.090142+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not implement these traits directly, but inherit from a library. `jawn-parser-1.3.1` fixes this issue and users are advised to upgrade. For users unable to upgrade override `objectContext()` to use a collision-safe collection.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-21653"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vc89-hccf-rq55</id>
    <title>GHSA-vc89-hccf-rq55 — Hash collision in typelevel jawn</title>
    <updated>2026-10-03T21:34:43.090177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.typelevel:jawn-parser_0.25, Maven: org.typelevel:jawn-parserg, Maven: org.typelevel:jawn-parser_0.27, Maven: org.typelevel:jawn-parser_2.10, Maven: org.typelevel:jawn-parser_2.11, Maven: org.typelevel:jawn-parser_2.12, Maven: org.typelevel:jawn-parser_2.13, Maven: org.typelevel:jawn-parser_2.13.0-M5, Maven: org.typelevel:jawn-parser_2.13.0-RC1, Maven: org.typelevel:jawn-parser_2.13.0-RC2 and 8 more</p>
<p>### Impact</p>
<p>Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to a hash collision attack.  Most applications do not implement these traits directly, but inherit from a library:</p>
<p>Affected implementations include:
* `org.http4s` :: `http4s-play-json`
* `org.typelevel :: jawn-ast` (&lt; 0.8.0)
* `org.typelevel :: jawn-play` (discontinued)
* `org.typelevel :: jawn-rojoma` (discontinued)
* `org.typelevel :: jawn-spray` (discontinued)</p>
<p>Unaffected implementations include:
* `io.argonaut :: argonaut-jawn`
* `io.circe :: circe-parser`
* `org.typelevel :: jawn-ast` (&gt;= 0.8.0)
* `org.typelevel :: jawn-json4s` (discontinued)
* `org.typelevel :: jawn-argonaut` (discontinued)</p>
<p>### Patches</p>
<p>`jawn-parser-1.3.2` fixes the issue.</p>
<p>### Workarounds</p>
<p>Override `objectContext()` to use a collision-safe collection.  See [the patch](https://github.com/typelevel/jawn/pull/390/files) for an example in both `SimpleFacade` and `MutableFacade`.</p>
<p>### References</p>
<p>* https://github.com/typelevel/jawn/pull/390</p>
<p>### Credits</p>
<p>* @kag0, for the report and the patch</p>
<p>### For more information
If you have any questions or comments about this advisory:
* Open an issue in [typelevel/jawn](https://github.com/typelevel/jawn)
* E-mail a maintainer:
  * [@rossabaker](mailto:ross@rossabaker.com)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vc89-hccf-rq55"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-21653</id>
    <title>gsd-2022-21653</title>
    <updated>2026-10-03T21:34:43.090241+00:00</updated>
    <content>gsd-2022-21653</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-21653"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0011-1</id>
    <title>openSUSE-SU-2022:0011-1 — Security update for jawn</title>
    <updated>2026-10-03T21:34:43.090256+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for jawn</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0011-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21653</id>
    <title>UBUNTU-CVE-2022-21653</title>
    <updated>2026-10-03T21:34:43.090274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: jawn, Ubuntu:22.04:LTS: jawn, Ubuntu:24.04:LTS: jawn, Ubuntu:25.10: jawn, Ubuntu:26.04:LTS: jawn</p>
<p>Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not implement these traits directly, but inherit from a library. `jawn-parser-1.3.1` fixes this issue and users are advised to upgrade. For users unable to upgrade override `objectContext()` to use a collision-safe collection.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21653"/>
  </entry>
</feed>
