PT-2026-65815 · Dave Gamble · Cjson

CVE-2026-67217

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply patch() in cJSON Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully validated, so the target document is mutated while cJSONUtils ApplyPatches() or cJSONUtils ApplyPatchesCaseSensitive() returns a failure status. An attacker who can supply the patch document can destroy addressable members of the target document even though the API reports that the patch failed, defeating the all-or-nothing behavior callers rely on to reject bad patches.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67217

Affected Products

Cjson