← Vulnerability feed

Vulnerability record · CVE-2026-67215 · published 29 July 2026

CVE-2026-67215: Davegamble cjson vulnerability

DDavegamble · Cjson

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service.

8.7 CVSS 4.0 High EPSS 0.70% · top 48.8% CWE-674 · CWE-674
8.7CVSS 4.0 base score
0.70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 2 tagged exploit
4 Aug 2026Last modified by NVD

Description

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-67215 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-57052Davegamble cjson out-of-bounds read vulnerabilitycJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers t…EPSS 0.74%9.8CVE-2019-11834Davegamble cjson out-of-bounds read vulnerabilitycJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.EPSS 2.5%9.8CVE-2019-11835Davegamble cjson out-of-bounds read vulnerabilitycJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.EPSS 2.6%9.8CVE-2016-10749Davegamble cjson out-of-bounds read vulnerabilityparse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a…EPSS 2.5%9.8CVE-2018-1000217Davegamble cjson use after free vulnerabilityDave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corr…EPSS 1.8%8.8CVE-2018-1000216Davegamble cjson double free vulnerabilityDave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. …EPSS 1.5%8.2CVE-2026-67216Davegamble cjson vulnerabilitycJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each …EPSS 0.65%7.5CVE-2023-50471Davegamble cjson null pointer dereference vulnerabilitycJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2026-67215), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.