Resource exhaustion in parsson - CVE-2026-9563

 

Resource exhaustion in parsson - CVE-2026-9563

Published: July 28, 2026


Vulnerability identifier: #VU139809
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9563
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to Eclipse Parsson did not enforce a default maximum on the number of characters consumed while parsing a single JSON document. Applications that parse attacker- controlled JSON can be forced to consume excessive CPU and memory by processing very large documents, including large arrays, objects, strings, numbers, whitespace, or nested structures, resulting in a denial of service. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

parsson
Enterprise Application Runtimes
Cloud Pak for Applications
WebSphere Hybrid Edition
webMethods ControlPlane
IBM SPSS Analytic Server
IBM SPSS Collaboration and Deployment Services
IBM WebSphere Application Server Liberty

How to mitigate CVE-2026-9563

Install updates from vendor's website.

parsson - update to 1.1.8
webMethods ControlPlane - update to 11.1 Fix11
IBM WebSphere Application Server Liberty - update to 26.0.0.8

External References

Related Security Bulletins