CVE-2026-87933

NameCVE-2026-87933
DescriptionA vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cjson (PTS)bookworm, bookworm (security)1.7.15-1+deb12u4vulnerable
trixie (security), trixie1.7.18-3.1+deb13u1vulnerable
forky, sid1.7.19-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cjsonsource(unstable)(unfixed)

Notes

https://github.com/DaveGamble/cJSON/issues/1060
https://github.com/DaveGamble/cJSON/pull/1065

Search for package or bug name: Reporting problems