CVE-2021-27568

json-smart JWT Parser Crash: stopped at runtime

Waratek RASP already blocks this exploit at runtime, inside the JVM - with no application change, no vendor patch, and no downtime.

Published February 23, 2021 · Updated November 21, 2024

Mitigated by Waratek MEDIUM CVSS 5.9 v3.1

The vulnerability

Denial of service / information exposure via uncaught parsing exception

json-smart's parser throws a NumberFormatException on certain malformed numeric input but callers never catch it. Because json-smart sits underneath Nimbus JOSE+JWT in many JWT validation stacks, an attacker can send a crafted token or payload that crashes the parsing application or leaks internal state through the uncaught exception.

Affected softwarenetplex json-smart (json-smart-v1 / json-smart-v2)
Affected versionsjson-smart-v1 through 2015-10-23 build; json-smart-v2 through 2.4
WeaknessImproper handling of exceptional conditions (CWE-754)
Published2021-02-23
SeverityMEDIUM · CVSS 5.9

Running an affected version? We can help.

Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.

Talk to us about protection

How Waratek RASP stops it

Blocked at runtime by Waratek RASP

Waratek RASP ships a patch rule that blocks exploitation at the exact point the dangerous operation is attempted, inside the JVM.

Runtime, not perimeter

Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.

No code changes

Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.

Zero false positives

Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.

Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.

Common questions

json-smart JWT Parser Crash FAQ

Is json-smart JWT Parser Crash (CVE-2021-27568) exploitable?

CVE-2021-27568 carries a CVSS 5.9/10 (MEDIUM) rating and affects netplex json-smart (json-smart-v1 / json-smart-v2) json-smart-v1 through 2015-10-23 build; json-smart-v2 through 2.4. json-smart's parser throws a NumberFormatException on certain malformed numeric input but callers never catch it. Because json-smart sits underneath Nimbus JOSE+JWT in many JWT validation stacks, an attacker can send a crafted token or payload that crashes the parsing application or leaks internal state through the uncaught exception.

How does Waratek mitigate json-smart JWT Parser Crash (CVE-2021-27568)?

Waratek RASP blocks exploitation of json-smart JWT Parser Crash (CVE-2021-27568) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.

How quickly was json-smart JWT Parser Crash (CVE-2021-27568) exploited after disclosure?

A working exploit for CVE-2021-27568 appeared within 1596 days of its NVD disclosure, on July 7, 2025.

Protect your apps in production

Get protected against json-smart JWT Parser Crash - without code changes or redeploying

Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2021-27568 and attacks like it, and get you covered in production.