---
cve: "CVE-2026-9563"
severity: "HIGH"
cvss: 7.5
epss: "35%"
vendor: "Eclipse Foundation"
kev: false
exploited: false
published: "2026-07-02 07:33:25"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T13:22:46+02:00"
---

# CVE-2026-9563

> 7.5 HIGH · 🧪 PoC

## Beschreibung

In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while parsing a single JSON document. Applications that parse attacker- controlled JSON can be forced to consume excessive CPU and memory by processing very large documents, including large arrays, objects, strings, numbers, whitespace, or nested structures, resulting in a denial of service. Eclipse Parsson 1.1.8 introduces a configurable maximum parsing limit with a default limit of 15 million parser-consumed characters.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- 9c79773abbe152babe5a79b280a43c8e91acf6b6 (Commit)
- 134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c (Commit)

## Referenzen

- <https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c>
- <https://github.com/eclipse-ee4j/parsson/pull/169>
- <https://repo.maven.apache.org/maven2/org/eclipse/parsson/parsson/1.1.8/>
- <https://github.com/eclipse-ee4j/parsson/tree/1.1.8>
- <https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/444>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-9563) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
