CVE-2026-24802
MEDIUMjsonrpc4j <= 1.6.0 - Denial of Service via Infinite Loop in NoCloseOutputStream
Title source: llmDescription
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in briandilley jsonrpc4j (src/main/java/com/googlecode/jsonrpc4j modules). This vulnerability is associated with program files NoCloseOutputStream.Java. This issue affects jsonrpc4j: through 1.6.0.
References (1)
Core 1
Core References
Issue Tracking patch
https://github.com/briandilley/jsonrpc4j/pull/333
Scores
CVSS v4
5.3
EPSS
0.0042
EPSS Percentile
33.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:L/AU:Y/R:A/V:D/RE:M/U:Amber
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-835
Status
published
Products (2)
briandilley/jsonrpc4j
< 1.6.0
com.github.briandilley.jsonrpc4j/jsonrpc4j
0 - 1.7.0Maven
Published
Jan 27, 2026
Tracked Since
Feb 18, 2026