Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-67215

5 дней назад

(cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading t ...)

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-67215

5 дней назад

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-67215

5 дней назад

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading t ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5q3m-r3x7-8phg

5 дней назад

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-10702

10 дней назад

Уязвимость функций cJSONUtils_ApplyPatches() и cJSONUtils_ApplyPatchesCaseSensitive() библиотеки для работы с JSON-объектами в C cJSON, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-67215

(cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading t ...)

CVSS3: 7.5
0%
Низкий
5 дней назад
nvd логотип
CVE-2026-67215

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service.

CVSS3: 7.5
0%
Низкий
5 дней назад
debian логотип
CVE-2026-67215

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading t ...

CVSS3: 7.5
0%
Низкий
5 дней назад
github логотип
GHSA-5q3m-r3x7-8phg

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service.

CVSS3: 7.5
0%
Низкий
5 дней назад
fstec логотип
BDU:2026-10702

Уязвимость функций cJSONUtils_ApplyPatches() и cJSONUtils_ApplyPatchesCaseSensitive() библиотеки для работы с JSON-объектами в C cJSON, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
10 дней назад

Уязвимостей на страницу