DTStack Chunjun Deserialization Vulnerability in GsonUtil

Vulnerability

A deserialization of untrusted data vulnerability has been identified in DTStack Chunjun versions prior to 1.16.1. This issue arises in the 'GsonUtil.java' file within the 'chunjun-core' module, where improper handling of JSON parsing can lead to stack overflow vulnerabilities.

Impact

Exploitation of this vulnerability can cause a stack overflow, potentially leading to a denial-of-service condition.

Remediation

Users can update to Chunjun version 1.16.1 or later to address this vulnerability.

Added: Mar 24, 2026, 4:30 AM
Updated: Mar 24, 2026, 4:30 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.7
remediation
0.0
relevance
4.6
threat
6.4
urgency
5.7
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.