{"id":"GHSA-hcx3-3q5c-r5v6","summary":"jsonrpc4j has Infinite Loop in RPC Stream Writer ","details":"Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in briandilley jsonrpc4j (src/main/java/com/googlecode/jsonrpc4j modules). This vulnerability is associated with program files NoCloseOutputStream.Java.\n\nThis issue affects jsonrpc4j: through 1.6.0.","aliases":["CVE-2026-24802"],"modified":"2026-02-03T03:07:17.525286Z","published":"2026-01-27T09:30:30Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-01-28T15:49:27Z","nvd_published_at":"2026-01-27T09:15:50Z","cwe_ids":["CWE-835"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24802"},{"type":"WEB","url":"https://github.com/briandilley/jsonrpc4j/pull/333"},{"type":"WEB","url":"https://github.com/briandilley/jsonrpc4j/commit/087f5268eaf901f90d1e84062def77faa52ad8b2"},{"type":"WEB","url":"https://github.com/briandilley/jsonrpc4j"}],"affected":[{"package":{"name":"com.github.briandilley.jsonrpc4j:jsonrpc4j","ecosystem":"Maven","purl":"pkg:maven/com.github.briandilley.jsonrpc4j/jsonrpc4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.0"}]}],"versions":["1.0","1.1","1.2.0","1.3.3","1.3.3-RC0","1.4.0","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.5.0","1.5.1","1.5.2","1.5.3","1.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-hcx3-3q5c-r5v6/GHSA-hcx3-3q5c-r5v6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:L/AU:Y/R:A/V:D/RE:M/U:Amber"}]}