CVE-2026-87933
Deferred Deferred - Pending Action

Use After Free in cJSON via cJSONUtils_MergePatch

Vulnerability report for CVE-2026-87933, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: VulDB

Description

A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
davegamble cjson to 1.7.19 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-87933 is a heap-use-after-free (UAF) vulnerability in the cJSON library's cJSONUtils_MergePatch() function. The issue occurs when the patch argument is a non-object subtree like a scalar, array, or NULL. The function incorrectly deletes the target object first, freeing patch memory if it is a subtree, then tries to duplicate the already-freed patch. This leads to a UAF read detected by AddressSanitizer.

Detection Guidance

To detect this vulnerability, compile the cJSON library with AddressSanitizer (ASan) and run tests or applications using cJSONUtils_MergePatch(). Use the PoC from issue #1060 to trigger the UAF. Check for crashes or ASan reports indicating heap-use-after-free in cJSONUtils_MergePatch().

Commands: git clone https://github.com/DaveGamble/cJSON.git; cd cJSON; git checkout <vulnerable version>; gcc -fsanitize=address -fno-omit-frame-pointer test.c -o test -I. -L. -lcjson; ./test. Use valgrind --tool=memcheck --leak-check=full ./your_application.

Impact Analysis

This vulnerability may allow remote attackers to execute arbitrary code or cause a denial of service by triggering a use-after-free condition. Applications using vulnerable cJSON versions for JSON patching could crash or behave unpredictably if exploited.

Compliance Impact

This vulnerability involves a heap-use-after-free issue in the cJSON library's MergePatch function. While the CVE does not directly address compliance standards like GDPR or HIPAA, such memory corruption vulnerabilities can lead to data corruption, unauthorized access, or denial of service. These issues may violate requirements for data integrity, confidentiality, and availability in GDPR and HIPAA, potentially resulting in non-compliance if exploited in systems handling sensitive data.

Mitigation Strategies

Immediately update to the patched version of cJSON where the fix in pull request #1065 is merged. If updating is not possible, avoid using cJSONUtils_MergePatch() with non-object patches (scalars, arrays, or NULL). Implement input validation to reject non-object patches before calling the function.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87933. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart