A high-severity denial-of-service vulnerability, CVE-2026-67215, has been disclosed in DaveGamble cJSON through version 1.7.19. The flaw affects applications that process untrusted RFC 6902 JSON Patch input with cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(), where crafted add and copy operations can duplicate subtrees and drive document depth far beyond expected limits.
The crash occurs because cJSON_Delete() can recurse without a depth bound, leading to stack exhaustion. Advisory details note that CJSON_CIRCULAR_LIMIT is set to 10000, substantially higher than the parser's roughly 1000-level nesting limit, creating a path for remote attackers with no privileges or user interaction to terminate affected processes. The issue is tracked as CWE-674 and carries a CVSS v3.1 score vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, reflecting high availability impact.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
The CVE entry states that disclosure@vulncheck.com newly received CVE-2026-67215 on July 29, 2026. The vulnerability affects cJSON through version 1.7.19 and can cause denial of service via uncontrolled recursion and stack exhaustion when processing crafted JSON Patch input.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.