{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3adavegamblecjson/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-87933"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cJSON (\u003c= 1.7.19)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["DaveGamble"],"content_html":"\u003cp\u003eA use-after-free vulnerability (CVE-2026-87933) has been identified in the DaveGamble cJSON library, specifically within the cJSONUtils_MergePatch function in the file cJSON_Utils.c. The vulnerability affects all versions of the library up to and including 1.7.19. The flaw occurs due to improper memory management during the JSON merge patch operation, which can be triggered remotely. Given that a proof-of-concept exploit has been made public, there is a risk of exploitation by unauthenticated remote attackers. The vulnerability allows for arbitrary code execution or service disruption through memory corruption. At the time of this brief, an official patch for this issue is pending acceptance via a pull request. Defenders should audit applications utilizing cJSON 1.7.19 or earlier and prepare to upgrade once a stable fix is merged and released.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe impact of this vulnerability is significant, as cJSON is a widely used C library for JSON parsing. Successful exploitation can lead to unauthorized code execution, arbitrary memory access, or denial of service by crashing the application. Applications that accept and process external, untrusted JSON data via the vulnerable cJSONUtils_MergePatch function are at the highest risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of applications within the environment that statically or dynamically link against the DaveGamble cJSON library version 1.7.19 or earlier.\u003c/p\u003e\n\u003cp\u003eMonitor vendor repositories for the final merge and release of the fix for CVE-2026-87933. Once the patch is available, schedule an immediate update for all affected software. Given the availability of public exploits, prioritize internal applications that process user-supplied JSON input from the public internet.\u003c/p\u003e\n","date_modified":"2026-09-10T03:03:51Z","date_published":"2026-09-10T03:03:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cjson-use-after-free/","summary":"A publicly exploitable use-after-free vulnerability in the cJSONUtils_MergePatch function of the DaveGamble cJSON library allows for potential remote code execution or application crashes.","title":"Use-After-Free Vulnerability in cJSON cJSONUtils_MergePatch","url":"https://feed.craftedsignal.io/briefs/2026-09-cjson-use-after-free/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}