No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 29 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jul 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service. | |
| Title | cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion | |
| First Time appeared |
Davegamble
Davegamble cjson |
|
| Weaknesses | CWE-674 | |
| CPEs | cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Davegamble
Davegamble cjson |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-29T15:59:48.983Z
Reserved: 2026-07-28T19:20:19.157Z
Link: CVE-2026-67215
Updated: 2026-07-29T14:33:44.906Z
No data.
No data.
OpenCVE Enrichment
No data.