Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29036

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() to silently corrupt data or delete unintended keys, potentially bypassing authorization controls in applications that rely on JSON Patch for access-controlled data modification.

A flaw was found in cJSON, a JSON parser and generator. This vulnerability allows unauthenticated attackers to manipulate JSON Patch operations by supplying crafted JSON Pointer escape sequences. This can lead to silent corruption of data or the deletion of unintended keys, potentially bypassing authorization controls in applications that use cJSON for data modification. The flaw resides in the decode_pointer_inplace() function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8rpm-ostreeNot affected
Red Hat Hardened ImageschunkahNot affected
Red Hat OpenShift Container Platform 4rpm-ostreeNot affected
Red Hat Satellite 6cjsonAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-386
https://bugzilla.redhat.com/show_bug.cgi?id=2514418cJSON: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding

EPSS

Процентиль: 18%
0.00258
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
7 дней назад

cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() to silently corrupt data or delete unintended keys, potentially bypassing authorization controls in applications that rely on JSON Patch for access-controlled data modification.

CVSS3: 7.5
nvd
8 дней назад

cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() to silently corrupt data or delete unintended keys, potentially bypassing authorization controls in applications that rely on JSON Patch for access-controlled data modification.

CVSS3: 7.5
debian
8 дней назад

cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved na ...

CVSS3: 7.5
github
8 дней назад

cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() to silently corrupt data or delete unintended keys, potentially bypassing authorization controls in applications that rely on JSON Patch for access-controlled data modification.

EPSS

Процентиль: 18%
0.00258
Низкий

7.5 High

CVSS3