[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2022-40149":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":26,"aliases":27,"duplicate_of":9,"upstream":29,"downstream":30,"duplicates":63,"related":64,"reserved_at":9,"published_at":68,"modified_at":69,"state":70,"summary":71,"references_raw":80,"kevs":123,"epss":124,"epss_history":127,"metrics":391,"affected":405},"CVE-2022-40149","Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.",null,[11,20],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-121","Stack-based Buffer Overflow","A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).","weakness","Draft","Variant","High",[],{"_key":21,"id":21,"name":22,"description":23,"type":15,"status":16,"abstraction":24,"likelihood_of_exploit":18,"capec":25},"CWE-787","Out-of-bounds Write","The product writes data past the end, or before the beginning, of the intended buffer.","Base",[],[],[28],"GHSA-56h3-78gp-v83r",[],[31,33,35,37,39,41,43,45,47,49,51,53,55,57,59,61],{"_key":32},"OPENSUSE-SU-2024:12388-1",{"_key":34},"DLA-3184-1",{"_key":36},"DSA-5312-1",{"_key":38},"DEBIAN-CVE-2022-40149",{"_key":40},"RHSA-2023:3663",{"_key":42},"UBUNTU-CVE-2022-40149",{"_key":44},"USN-6177-1",{"_key":46},"RHSA-2025:4437",{"_key":48},"RHSA-2023:0552",{"_key":50},"RHSA-2023:0553",{"_key":52},"RHSA-2023:0554",{"_key":54},"RHSA-2025:4226",{"_key":56},"RHSA-2023:1043",{"_key":58},"RHSA-2023:1044",{"_key":60},"RHSA-2023:1045",{"_key":62},"RHSA-2023:3610",[],[65,66],{"_key":32},{"_key":67},"CGA-H3V5-5856-885R","2022-09-16T00:00:00.000Z","2025-04-21T13:49:51.304Z","Modified",{"cisa_kev":72,"cisa_ransomware":72,"cisa_vendor":9,"epss_severity":73,"epss_score":74,"severity":75,"severity_score":76,"severity_version":77,"severity_source":78,"severity_vector":79,"severity_status":70},false,"low",0.0055,"high",7.5,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",[81,90,95,100,105,110,114,119],{"url":82,"sources":83,"tags":86},"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46538",[84,78,85],"cve.org","osv_maven",[87,88,89],"Permissions Required","Third Party Advisory","WEB",{"url":91,"sources":92,"tags":93},"https://github.com/jettison-json/jettison/issues/45",[84,78,85],[94,88,89],"Issue Tracking",{"url":96,"sources":97,"tags":98},"https://lists.debian.org/debian-lts-announce/2022/11/msg00011.html",[84,78,85],[99,88,89],"Mailing List",{"url":101,"sources":102,"tags":103},"https://www.debian.org/security/2023/dsa-5312",[84,78,85],[104,88,89],"Vendor Advisory",{"url":106,"sources":107,"tags":108},"https://nvd.nist.gov/vuln/detail/CVE-2022-40149",[85],[109],"Advisory",{"url":111,"sources":112,"tags":113},"https://github.com/jettison-json/jettison/pull/49/files",[85],[89],{"url":115,"sources":116,"tags":117},"https://github.com/jettison-json/jettison",[85],[118],"PACKAGE",{"url":120,"sources":121,"tags":122},"https://github.com/jettison-json/jettison/releases/tag/jettison-1.5.1",[85],[89],[],{"date":125,"score":74,"percentile":126},"2026-06-04",0.68312,[128,132,135,138,141,144,147,150,152,155,158,161,164,166,169,173,176,179,182,185,188,191,194,197,199,202,205,208,211,214,217,219,222,225,227,230,232,235,238,241,244,246,249,252,255,258,261,264,267,270,273,276,279,282,285,288,290,293,295,298,301,304,307,310,313,316,319,322,325,328,330,333,336,339,342,345,348,351,354,357,361,364,367,370,373,376,379,382,385,388],{"date":129,"score":130,"percentile":131},"2025-11-04",0.00521,0.66012,{"date":133,"score":130,"percentile":134},"2025-11-05",0.65989,{"date":136,"score":130,"percentile":137},"2025-11-06",0.65985,{"date":139,"score":130,"percentile":140},"2025-11-07",0.65996,{"date":142,"score":130,"percentile":143},"2025-11-08",0.65995,{"date":145,"score":130,"percentile":146},"2025-11-09",0.65983,{"date":148,"score":130,"percentile":149},"2025-11-10",0.65975,{"date":151,"score":130,"percentile":146},"2025-11-11",{"date":153,"score":130,"percentile":154},"2025-11-12",0.66004,{"date":156,"score":130,"percentile":157},"2025-11-13",0.66014,{"date":159,"score":130,"percentile":160},"2025-11-14",0.66022,{"date":162,"score":130,"percentile":163},"2025-11-15",0.66018,{"date":165,"score":130,"percentile":131},"2025-11-16",{"date":167,"score":130,"percentile":168},"2025-11-17",0.66011,{"date":170,"score":171,"percentile":172},"2025-11-18",0.01337,0.78284,{"date":174,"score":171,"percentile":175},"2025-11-19",0.78292,{"date":177,"score":171,"percentile":178},"2025-11-20",0.783,{"date":180,"score":130,"percentile":181},"2025-11-21",0.66021,{"date":183,"score":130,"percentile":184},"2025-11-22",0.66029,{"date":186,"score":130,"percentile":187},"2025-11-23",0.66013,{"date":189,"score":130,"percentile":190},"2025-11-24",0.65999,{"date":192,"score":130,"percentile":193},"2025-11-25",0.66003,{"date":195,"score":130,"percentile":196},"2025-11-26",0.66008,{"date":198,"score":130,"percentile":187},"2025-11-27",{"date":200,"score":130,"percentile":201},"2025-11-28",0.65998,{"date":203,"score":130,"percentile":204},"2025-11-29",0.65979,{"date":206,"score":130,"percentile":207},"2025-11-30",0.65974,{"date":209,"score":130,"percentile":210},"2025-12-01",0.6613,{"date":212,"score":130,"percentile":213},"2025-12-02",0.66147,{"date":215,"score":130,"percentile":216},"2025-12-03",0.66145,{"date":218,"score":130,"percentile":207},"2025-12-04",{"date":220,"score":130,"percentile":221},"2025-12-05",0.65987,{"date":223,"score":130,"percentile":224},"2025-12-06",0.65992,{"date":226,"score":130,"percentile":221},"2025-12-07",{"date":228,"score":130,"percentile":229},"2025-12-08",0.65991,{"date":231,"score":130,"percentile":181},"2025-12-09",{"date":233,"score":130,"percentile":234},"2025-12-10",0.66069,{"date":236,"score":130,"percentile":237},"2025-12-11",0.6609,{"date":239,"score":130,"percentile":240},"2025-12-12",0.66115,{"date":242,"score":130,"percentile":243},"2025-12-13",0.66122,{"date":245,"score":130,"percentile":243},"2025-12-14",{"date":247,"score":130,"percentile":248},"2025-12-15",0.66118,{"date":250,"score":130,"percentile":251},"2025-12-16",0.66131,{"date":253,"score":130,"percentile":254},"2025-12-17",0.66146,{"date":256,"score":130,"percentile":257},"2025-12-18",0.66183,{"date":259,"score":130,"percentile":260},"2025-12-19",0.66198,{"date":262,"score":130,"percentile":263},"2025-12-20",0.66196,{"date":265,"score":130,"percentile":266},"2025-12-21",0.66187,{"date":268,"score":130,"percentile":269},"2025-12-22",0.66186,{"date":271,"score":130,"percentile":272},"2025-12-23",0.66181,{"date":274,"score":130,"percentile":275},"2025-12-24",0.66192,{"date":277,"score":130,"percentile":278},"2025-12-25",0.66223,{"date":280,"score":130,"percentile":281},"2025-12-26",0.6622,{"date":283,"score":130,"percentile":284},"2025-12-27",0.66274,{"date":286,"score":130,"percentile":287},"2025-12-28",0.66193,{"date":289,"score":130,"percentile":257},"2025-12-29",{"date":291,"score":130,"percentile":292},"2025-12-30",0.662,{"date":294,"score":130,"percentile":278},"2025-12-31",{"date":296,"score":130,"percentile":297},"2026-01-01",0.66399,{"date":299,"score":130,"percentile":300},"2026-01-02",0.66384,{"date":302,"score":130,"percentile":303},"2026-01-03",0.66385,{"date":305,"score":130,"percentile":306},"2026-01-04",0.66219,{"date":308,"score":130,"percentile":309},"2026-01-05",0.66203,{"date":311,"score":130,"percentile":312},"2026-01-06",0.66212,{"date":314,"score":130,"percentile":315},"2026-01-07",0.66233,{"date":317,"score":130,"percentile":318},"2026-01-08",0.66245,{"date":320,"score":130,"percentile":321},"2026-01-09",0.66255,{"date":323,"score":130,"percentile":324},"2026-01-10",0.66257,{"date":326,"score":130,"percentile":327},"2026-01-11",0.66247,{"date":329,"score":130,"percentile":315},"2026-01-12",{"date":331,"score":130,"percentile":332},"2026-01-13",0.66229,{"date":334,"score":130,"percentile":335},"2026-01-14",0.66263,{"date":337,"score":130,"percentile":338},"2026-01-15",0.66266,{"date":340,"score":130,"percentile":341},"2026-01-16",0.66284,{"date":343,"score":130,"percentile":344},"2026-01-17",0.66273,{"date":346,"score":130,"percentile":347},"2026-01-18",0.66256,{"date":349,"score":130,"percentile":350},"2026-01-19",0.6624,{"date":352,"score":130,"percentile":353},"2026-01-20",0.66253,{"date":355,"score":130,"percentile":356},"2026-01-21",0.66265,{"date":358,"score":359,"percentile":360},"2026-01-22",0.00536,0.66877,{"date":362,"score":359,"percentile":363},"2026-01-23",0.66908,{"date":365,"score":359,"percentile":366},"2026-01-24",0.66918,{"date":368,"score":359,"percentile":369},"2026-01-25",0.66886,{"date":371,"score":359,"percentile":372},"2026-01-26",0.66876,{"date":374,"score":359,"percentile":375},"2026-01-27",0.66885,{"date":377,"score":359,"percentile":378},"2026-01-28",0.66896,{"date":380,"score":359,"percentile":381},"2026-01-29",0.66898,{"date":383,"score":359,"percentile":384},"2026-01-30",0.66909,{"date":386,"score":359,"percentile":387},"2026-01-31",0.66911,{"date":389,"score":359,"percentile":390},"2026-02-01",0.6706,[392,399,403],{"source":84,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":393,"cvss_v4_0":9},{"baseScore":394,"baseSeverity":395,"vectorString":396,"impactScore":397,"exploitabilityScore":398},6.5,"MEDIUM","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",6,7.2,{"source":78,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":400,"cvss_v4_0":9},{"baseScore":76,"baseSeverity":401,"vectorString":79,"impactScore":397,"exploitabilityScore":402},"HIGH",10,{"source":85,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":404,"cvss_v4_0":9},{"baseScore":394,"baseSeverity":9,"vectorString":396,"impactScore":397,"exploitabilityScore":398},[406,417,427,433],{"ecosystem":9,"name":407,"vendor":408,"product":409,"cpe_part":410,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":411},"debian linux","debian","debian_linux","o",[412,415],{"version":413,"is_range":72,"range_type":414,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.0","cpe",{"version":416,"is_range":72,"range_type":414,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0",{"ecosystem":9,"name":418,"vendor":419,"product":418,"cpe_part":420,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":421},"jettison","jettison_project","a",[422],{"version":423,"is_range":424,"range_type":414,"version_start":9,"version_start_type":9,"version_end":425,"version_end_type":426,"fixed_in":9},"lte1.4.0",true,"1.4.0","including",{"ecosystem":9,"name":428,"vendor":418,"product":418,"cpe_part":420,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":429},"Jettison",[430],{"version":431,"is_range":424,"range_type":84,"version_start":432,"version_start_type":426,"version_end":425,"version_end_type":426,"fixed_in":9},">= unspecified, \u003C= 1.4.0","unspecified",{"ecosystem":434,"name":435,"vendor":436,"product":418,"cpe_part":9,"purl_type":437,"purl_namespace":436,"purl_name":418,"source":9,"versions":438},"Maven","org.codehaus.jettison:jettison","org.codehaus.jettison","maven",[439],{"version":440,"is_range":424,"range_type":441,"version_start":9,"version_start_type":9,"version_end":442,"version_end_type":443,"fixed_in":9},"lt1_5_1","ecosystem","1.5.1","excluding"]