Description
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service.
Published: 2026-07-29
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A recursion flaw in the cJSON library versions up to and including 1.7.19 allows an attacker to cause stack exhaustion by applying a crafted RFC 6902 JSON Patch that repeatedly copies and adds nested objects. The flaw manifests when cJSON_Delete and cJSON_Duplicate recurse without a practical bound, exceeding the parser’s 1000‑level nesting limit and destroying the process’s thread stack. This is a classic uncontrolled recursion vulnerability (CWE‑674) with a CVSS score of 8.7, reflecting a high‑severity denial‑of‑service impact.

Affected Systems

The vulnerability affects the cJSON library developed by DaveGamble. Any build of the library with a version number 1.7.19 or earlier is susceptible; newer releases are currently unimplicated.

Risk and Exploitability

The EPSS score is below 1 % and the issue is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation at present. Nonetheless, the attack vector is straightforward: an attacker who can supply a JSON Patch input to the vulnerable cJSONUtils_ApplyPatches functions can trigger the recursion, causing the host process to crash and deny service. No additional privileges or pre‑existing access are required beyond the ability to deliver the patch document.

Generated by OpenCVE AI on August 2, 2026 at 07:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the cJSON library to a version newer than 1.7.19; if no release exists, replace the library with a patched fork that imposes a recursion depth limit or removes the vulnerable functions.
  • Bypass or restrict the use of cJSONUtils_ApplyPatches and cJSONUtils_ApplyPatchesCaseSensitive by validating patch documents before application, ensuring that add and copy operations do not create nested structures above a safe threshold.
  • Deploy an application‑level watchdog or hard‑enforced stack size limits to mitigate any residual recursion that might bypass the library changes, thereby preventing accidental or malicious stack overflows.

Generated by OpenCVE AI on August 2, 2026 at 07:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service.
Title cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion
First Time appeared Davegamble
Davegamble cjson
Weaknesses CWE-674
CPEs cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*
Vendors & Products Davegamble
Davegamble cjson
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Davegamble Cjson
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-29T15:59:48.983Z

Reserved: 2026-07-28T19:20:19.157Z

Link: CVE-2026-67215

cve-icon Vulnrichment

Updated: 2026-07-29T14:33:44.906Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T14:16:35.187

Modified: 2026-08-04T15:09:26.327

Link: CVE-2026-67215

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T08:00:04Z

Weaknesses