See how json-path compares to other vendors in security performance
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
https://github.com/json-path/JsonPath/issues/973
json-path is vulnerable to a denial of service, caused by a stack-based buffer overflow in the Criteria.parse method. By sending a specially crafted input, a remote attacker could exploit this vulnerability to cause an uncontrolled recursion, and results in a denial of service condition.