๐Ÿ” CVE Alert

CVE-2026-67216

MEDIUM 5.9

cJSON cJSON_Compare Exponential Complexity Denial of Service

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred bytes (depth around 40) compared for equality consumes hours of CPU, and the cost roughly doubles with each additional level of nesting. An application that calls cJSON_Compare() on attacker-influenced JSON that is structurally equal to a reference document is exposed to a denial-of-service condition.

CWE CWE-407
Vendor davegamble
Product cjson
Published Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for davegamble cjson

Be the first to know when new medium vulnerabilities affecting davegamble cjson are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

DaveGamble / cJSON
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
joshua.hu: https://joshua.hu/cjson-json-parser-cve-vulnerabilities github.com: https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON.c#L3057-L3180 vulncheck.com: https://www.vulncheck.com/advisories/cjson-cjson-compare-exponential-complexity-denial-of-service