Description
A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-07
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote stack-based buffer overflow via JsonMergePatch.fromJson
Action: Patch or isolate
AI Analysis

Impact

A flaw was identified in java‑json‑tools’ json‑patch library, specifically in JsonMergePatch.fromJson in JsonMergePatchDeserializer.java. The vulnerability allows a crafted JSON merge patch to trigger a stack‑based buffer overflow. An attacker who can send a malicious payload to a component that uses this library can potentially corrupt memory or execute arbitrary code, leading to a crash or other loss of security.

Affected Systems

The affected product is java‑json‑tools’ json‑patch library, with all releases up to and including 1.13 impacted. No other vendors or products are listed; the CPE points exclusively to this open‑source library.

Risk and Exploitability

The CVSS score of 6.9 denotes moderate severity, and the EPSS score being less than 1% indicates a low but non‑zero exploitation probability. The vulnerability is already exploited in the wild, and because the attack vector is remote—it can be triggered by sending a malicious JSON patch to any exposed interface that invokes the library—systems that accept external JSON input are at risk. The issue is not yet listed in the CISA KEV catalog, but its availability in public code bases and remote nature warrant timely mitigation.

Generated by OpenCVE AI on September 21, 2026 at 05:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the json‑patch project's release notes for a fixed version and upgrade to that release if it incorporates the fix.
  • If a patch is not currently available, implement strict input validation, rejecting or sanitizing untrusted JSON merge patch payloads before passing them to the library.
  • Add network or application controls to restrict which callers can supply merge patches, limiting exposure to trusted internal services only.

Generated by OpenCVE AI on September 21, 2026 at 05:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title java-json-tools json-patch JsonMergePatchDeserializer.java JsonMergePatch.fromJson stack-based overflow
First Time appeared Java-json-tools
Java-json-tools json-patch
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:java-json-tools:json-patch:*:*:*:*:*:*:*:*
Vendors & Products Java-json-tools
Java-json-tools json-patch
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Java-json-tools Json-patch
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-08T13:03:26.676Z

Reserved: 2026-09-07T05:32:59.436Z

Link: CVE-2026-86318

cve-icon Vulnrichment

Updated: 2026-09-08T13:03:05.833Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T15:17:34.040

Modified: 2026-09-08T14:17:34.430

Link: CVE-2026-86318

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-07T14:30:14Z

Links: CVE-2026-86318 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T06:00:09Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-121

    Stack-based Buffer Overflow