<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:41:40 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-232849</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232849</link>
      <description>EUVD-2026-232849</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232849</guid>
    </item>
    <item>
      <title>fkie_cve-2022-21653</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21653</link>
      <description>&lt;p&gt;Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don&amp;#39;t override `objectContext()` are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not implement these traits directly, but inherit from a library. `jawn-parser-1.3.1` fixes this issue and users are advised to upgrade. For users unable to upgrade override `objectContext()` to use a collision-safe collection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don&amp;#39;t override `objectContext()` are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not implement these traits directly, but inherit from a library. `jawn-parser-1.3.1` fixes this issue and users are advised to upgrade. For users unable to upgrade override `objectContext()` to use a collision-safe collection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-21653</guid>
    </item>
    <item>
      <title>GHSA-vc89-hccf-rq55 — Hash collision in typelevel jawn</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vc89-hccf-rq55</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.typelevel:jawn-parser_0.25, Maven: org.typelevel:jawn-parserg, Maven: org.typelevel:jawn-parser_0.27, Maven: org.typelevel:jawn-parser_2.10, Maven: org.typelevel:jawn-parser_2.11, Maven: org.typelevel:jawn-parser_2.12, Maven: org.typelevel:jawn-parser_2.13, Maven: org.typelevel:jawn-parser_2.13.0-M5, Maven: org.typelevel:jawn-parser_2.13.0-RC1, Maven: org.typelevel:jawn-parser_2.13.0-RC2 and 8 more&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don&amp;#39;t override `objectContext()` are vulnerable to a hash collision attack.  Most applications do not implement these traits directly, but inherit from a library:&lt;/p&gt;
&lt;p&gt;Affected implementations include:
* `org.http4s` :: `http4s-play-json`
* `org.typelevel :: jawn-ast` (&amp;lt; 0.8.0)
* `org.typelevel :: jawn-play` (discontinued)
* `org.typelevel :: jawn-rojoma` (discontinued)
* `org.typelevel :: jawn-spray` (discontinued)&lt;/p&gt;
&lt;p&gt;Unaffected implementations include:
* `io.argonaut :: argonaut-jawn`
* `io.circe :: circe-parser`
* `org.typelevel :: jawn-ast` (&amp;gt;= 0.8.0)
* `org.typelevel :: jawn-json4s` (discontinued)
* `org.typelevel :: jawn-argonaut` (discontinued)&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;`jawn-parser-1.3.2` fixes the issue.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Override `objectContext()` to use a collision-safe collection.  See [the patch](https://github.com/typelevel/jawn/pull/390/files) for an example in both `SimpleFacade` and `MutableFacade`.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://github.com/typelevel/jawn/pull/390&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;* @kag0, for the report and the patch&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [typelevel/jawn](https://github.com/typelevel/jawn)
* E-mail a maintainer:
  * [@rossabaker](mailto:ross@rossabaker.com)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.typelevel:jawn-parser_0.25, Maven: org.typelevel:jawn-parserg, Maven: org.typelevel:jawn-parser_0.27, Maven: org.typelevel:jawn-parser_2.10, Maven: org.typelevel:jawn-parser_2.11, Maven: org.typelevel:jawn-parser_2.12, Maven: org.typelevel:jawn-parser_2.13, Maven: org.typelevel:jawn-parser_2.13.0-M5, Maven: org.typelevel:jawn-parser_2.13.0-RC1, Maven: org.typelevel:jawn-parser_2.13.0-RC2 and 8 more&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don&amp;#39;t override `objectContext()` are vulnerable to a hash collision attack.  Most applications do not implement these traits directly, but inherit from a library:&lt;/p&gt;
&lt;p&gt;Affected implementations include:
* `org.http4s` :: `http4s-play-json`
* `org.typelevel :: jawn-ast` (&amp;lt; 0.8.0)
* `org.typelevel :: jawn-play` (discontinued)
* `org.typelevel :: jawn-rojoma` (discontinued)
* `org.typelevel :: jawn-spray` (discontinued)&lt;/p&gt;
&lt;p&gt;Unaffected implementations include:
* `io.argonaut :: argonaut-jawn`
* `io.circe :: circe-parser`
* `org.typelevel :: jawn-ast` (&amp;gt;= 0.8.0)
* `org.typelevel :: jawn-json4s` (discontinued)
* `org.typelevel :: jawn-argonaut` (discontinued)&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;`jawn-parser-1.3.2` fixes the issue.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Override `objectContext()` to use a collision-safe collection.  See [the patch](https://github.com/typelevel/jawn/pull/390/files) for an example in both `SimpleFacade` and `MutableFacade`.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://github.com/typelevel/jawn/pull/390&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;* @kag0, for the report and the patch&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [typelevel/jawn](https://github.com/typelevel/jawn)
* E-mail a maintainer:
  * [@rossabaker](mailto:ross@rossabaker.com)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vc89-hccf-rq55</guid>
    </item>
    <item>
      <title>gsd-2022-21653</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-21653</link>
      <description>gsd-2022-21653</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-21653</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0011-1 — Security update for jawn</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0011-1</link>
      <description>&lt;p&gt;Security update for jawn&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for jawn&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0011-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-21653</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21653</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: jawn, Ubuntu:22.04:LTS: jawn, Ubuntu:24.04:LTS: jawn, Ubuntu:25.10: jawn, Ubuntu:26.04:LTS: jawn&lt;/p&gt;
&lt;p&gt;Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don&amp;#39;t override `objectContext()` are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not implement these traits directly, but inherit from a library. `jawn-parser-1.3.1` fixes this issue and users are advised to upgrade. For users unable to upgrade override `objectContext()` to use a collision-safe collection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: jawn, Ubuntu:22.04:LTS: jawn, Ubuntu:24.04:LTS: jawn, Ubuntu:25.10: jawn, Ubuntu:26.04:LTS: jawn&lt;/p&gt;
&lt;p&gt;Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don&amp;#39;t override `objectContext()` are vulnerable to a hash collision attack which may result in a denial of service. Most applications do not implement these traits directly, but inherit from a library. `jawn-parser-1.3.1` fixes this issue and users are advised to upgrade. For users unable to upgrade override `objectContext()` to use a collision-safe collection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21653</guid>
    </item>
  </channel>
</rss>
