{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cjson-1.5.0-1.7.19/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-29036"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cJSON (1.5.0-1.7.19)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["cJSON"],"content_html":"\u003cp\u003ecJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability within the decode_pointer_inplace() function of cJSON_Utils.c. The flaw exists in how the library handles JSON Pointer escape sequences, specifically the '~0' and '~1' sequences defined in RFC 6902. An unauthenticated attacker providing malicious JSON Patch input to an application that utilizes cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() can force the library to reference incorrect keys within a JSON object. This allows for data corruption, unauthorized key deletion, or the modification of sensitive configuration fields, potentially bypassing security controls in downstream applications. Because cJSON is a ubiquitous C library for JSON parsing and utility, the scope of affected applications is extensive, requiring developers to audit their use of the cJSON_Utils module and apply patches to version 1.7.20 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to applications relying on JSON Patch operations for data mutation or access control. Successful exploitation leads to unauthorized modification or deletion of data within JSON objects. While the library itself is OS-agnostic, the impact is determined by the permissions of the application processing the malicious payload. This could result in privilege escalation or business logic bypasses depending on how the application handles the manipulated JSON structures.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all applications within your environment that bundle or link against cJSON versions 1.5.0 through 1.7.19.\u003c/li\u003e\n\u003cli\u003ePrioritize patching for internet-facing applications that expose JSON Patch functionality to unauthenticated users.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on all JSON Patch operations before passing the input to the cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() functions to ensure escape sequences do not reference unauthorized keys.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, implement application-layer controls to sanitize JSON Pointer paths by filtering for unexpected '~' characters before processing.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T23:52:45Z","date_published":"2026-08-11T23:52:45Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cjson-vulnerability/","summary":"cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved reference vulnerability in cJSON_Utils that allows unauthenticated attackers to manipulate JSON object keys via crafted RFC 6902 JSON Pointer escape sequences.","title":"CVE-2026-29036 Incorrectly-Resolved Reference in cJSON","url":"https://feed.craftedsignal.io/briefs/2026-08-cjson-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - CJSON (1.5.0-1.7.19)","version":"https://jsonfeed.org/version/1.1"}