CVE-2026-87933
A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- CWE
- CWE-416, CWE-119
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- DaveGamble cJSON
- DaveGamble cJSON
- DaveGamble cJSON
- DaveGamble cJSON
- DaveGamble cJSON
- DaveGamble cJSON
- DaveGamble cJSON
- DaveGamble cJSON
Weakness type
Related vulnerabilities
- CVE-2026-87877 — zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free via Setters Called After close()
- CVE-2026-87825 — zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free of Compression and Decompression Dictionaries
- CVE-2026-87617 — Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87448 — Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...
- CVE-2026-87634 — Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...
- CVE-2026-87609 — Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87526 — Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87455 — Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...