A public disclosure detailed 33 vulnerabilities in the widely used C JSON library cJSON, affecting versions through 1.7.19 and prompting warnings for organizations that parse attacker-controlled JSON. The reported issues include memory-safety bugs, denial-of-service conditions, and logic flaws that can cause silent data loss or operations on the wrong object member. An oss-sec post said some of the problems had previously been reported with proof-of-concept code and unmerged fixes, while the library's development was described as largely stagnant.
One of the tracked issues, CVE-2026-67216, is a CWE-407 algorithmic complexity flaw in cJSON_Compare() that can be exploited for remote CPU exhaustion. The vulnerable function recursively traverses shared JSON subtrees twice without a depth guard, causing comparison time to grow exponentially with nesting depth; a small but deeply nested JSON document can therefore tie up a system for hours. Advisories recommend upgrading to a patched release when available, avoiding cJSON_Compare() on deeply nested input, validating JSON structure before comparison, and assessing whether cJSON should be replaced in exposed applications.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
An oss-sec mailing list post highlighted the public writeup about 33 cJSON vulnerabilities and warned organizations to assess replacing the library where attacker-controlled JSON is parsed. The post also noted that CVE-2026-67215, CVE-2026-67216, and CVE-2026-67217 reference the disclosed writeup.
CVE-2026-67216 was published for an exponential-complexity denial-of-service vulnerability in cJSON through version 1.7.19. The flaw stems from inefficient recursive traversal in cJSON_Compare(), allowing deeply nested JSON comparisons to consume excessive CPU time.
A public writeup reported 33 security issues in the cJSON library affecting versions up to and including 1.7.19. The disclosure said the first 13 issues included memory-safety and denial-of-service flaws, while the rest were logic bugs that could cause silent data loss or operations on the wrong object member.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcecvefeed.io
Open sourcejoshua.hu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.