Description
A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
Published: 2026-09-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free Memory Corruption
Action: Patch
AI Analysis

Impact

The vulnerability resides in the cJSONUtils_MergePatch function within DaveGamble's cJSON library. When a crafted JSON input is processed, the function frees memory and then attempts to access that freed memory, creating a use‑after‑free condition. This can lead to memory corruption, application crashes, or potentially unintended execution of code, though the CVE description does not confirm arbitrary code execution.

Affected Systems

All released versions of DaveGamble cJSON from the initial release through version 1.7.19 are affected. Versions beyond 1.7.19 have not been verified to contain the fix and should be considered at risk until a patch is applied.

Risk and Exploitability

The CVSS score of 6.9 signals moderate severity, the EPSS score of less than 1% indicates low exposure probability, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the exploit is public and can be triggered over a remote interface, which raises the potential risk for any system that uses an unpatched copy of the library.

Generated by OpenCVE AI on September 21, 2026 at 06:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official upgrade to a cJSON release that merges the security fix, addressing the use‑after‑free (CWE‑416) and related buffer issues (CWE‑119).
  • If an upgrade is not feasible immediately, remove or disable all calls to cJSONUtils_MergePatch in your code base, thereby eliminating the unsafe memory access and any associated integer wrap‑around (CWE‑825).
  • Continuously monitor the cJSON GitHub repository and vendor advisories, and install any subsequent patches or updates as soon as they become available.

Generated by OpenCVE AI on September 21, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
Title DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free
First Time appeared Davegamble
Davegamble cjson
Weaknesses CWE-119
CWE-416
CPEs cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*
Vendors & Products Davegamble
Davegamble cjson
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Davegamble Cjson
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-10T19:06:09.220Z

Reserved: 2026-09-09T16:21:04.414Z

Link: CVE-2026-87933

cve-icon Vulnrichment

Updated: 2026-09-10T18:13:18.876Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T01:16:35.650

Modified: 2026-09-10T20:17:31.073

Link: CVE-2026-87933

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T00:15:08Z

Links: CVE-2026-87933 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T06:30:09Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free

  • CWE-825

    Expired Pointer Dereference