maven package report

Is com.typesafe.play:play safe?

3 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
1.4%

chance of exploitation in the next 30 days

xyz score
3.4

CyberXYZ composite, out of 10

fig. 01 — GHSA-h48w-c35p-6m8x, the advisory selected below

// advisories

GHSA-h48w-c35p-6m8x

HIGHCVE-2020-27196

An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly parses a payload given a Content-Type header. A deep JSON structure sent to a valid POST endpoint (that may or may not expect JSON payloads) causes a StackOverflowError and Denial of Service.

Affected
>= 2.8.0, < 2.8.3, >= 2.6.0, < 2.7.6
Fixed in
2.8.3
Weakness
CWE-787
Published
2022-02-10
Source
github

GHSANVDMITREreferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 01:45 UTC. The most recent advisory here was published 2022-02-10. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is com.typesafe.play:play safe? maven package security report | CyberXYZ