A high-severity denial-of-service vulnerability, CVE-2026-67215, has been disclosed in DaveGamble cJSON through version 1.7.19. The flaw affects applications that process untrusted RFC 6902 JSON Patch input with cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(), where crafted add and copy operations can duplicate subtrees and drive document depth far beyond expected limits.
The crash occurs because cJSON_Delete() can recurse without a depth bound, leading to stack exhaustion. Advisory details note that CJSON_CIRCULAR_LIMIT is set to 10000, substantially higher than the parser's roughly 1000-level nesting limit, creating a path for remote attackers with no privileges or user interaction to terminate affected processes. The issue is tracked as CWE-674 and carries a CVSS v3.1 score vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, reflecting high availability impact.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
The CVE entry states that disclosure@vulncheck.com newly received CVE-2026-67215 on July 29, 2026. The vulnerability affects cJSON through version 1.7.19 and can cause denial of service via uncontrolled recursion and stack exhaustion when processing crafted JSON Patch input.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.