Impact
A flaw was identified in java‑json‑tools’ json‑patch library, specifically in JsonMergePatch.fromJson in JsonMergePatchDeserializer.java. The vulnerability allows a crafted JSON merge patch to trigger a stack‑based buffer overflow. An attacker who can send a malicious payload to a component that uses this library can potentially corrupt memory or execute arbitrary code, leading to a crash or other loss of security.
Affected Systems
The affected product is java‑json‑tools’ json‑patch library, with all releases up to and including 1.13 impacted. No other vendors or products are listed; the CPE points exclusively to this open‑source library.
Risk and Exploitability
The CVSS score of 6.9 denotes moderate severity, and the EPSS score being less than 1% indicates a low but non‑zero exploitation probability. The vulnerability is already exploited in the wild, and because the attack vector is remote—it can be triggered by sending a malicious JSON patch to any exposed interface that invokes the library—systems that accept external JSON input are at risk. The issue is not yet listed in the CISA KEV catalog, but its availability in public code bases and remote nature warrant timely mitigation.
OpenCVE Enrichment