Resource exhaustion in parsson - CVE-2026-9563
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to Eclipse Parsson did not enforce a default maximum on the number of characters consumed while parsing a single JSON document. Applications that parse attacker- controlled JSON can be forced to consume excessive CPU and memory by processing very large documents, including large arrays, objects, strings, numbers, whitespace, or nested structures, resulting in a denial of service. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Enterprise Application Runtimes
Cloud Pak for Applications
WebSphere Hybrid Edition
webMethods ControlPlane
IBM SPSS Analytic Server
IBM SPSS Collaboration and Deployment Services
IBM WebSphere Application Server Liberty
How to mitigate CVE-2026-9563
webMethods ControlPlane - update to 11.1 Fix11
IBM WebSphere Application Server Liberty - update to 26.0.0.8
External References
- https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c
- https://github.com/eclipse-ee4j/parsson/pull/169
- https://github.com/eclipse-ee4j/parsson/tree/1.1.8
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/444
- https://repo.maven.apache.org/maven2/org/eclipse/parsson/parsson/1.1.8/
Related Security Bulletins
- Resource exhaustion in Eclipse Parsson
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- Resource exhaustion in IBM Cloud Pak for Applications
- Resource exhaustion in IBM Enterprise Application Runtimes
- Resource exhaustion in IBM WebSphere Hybrid Edition
- IBM WebSphere Application Server - Liberty update for Eclipse Parsson
- Multiple vulnerabilities in IBM SPSS Analytic Server
- Resource exhaustion in IBM webMethods API ControlPlane (on-prem)