CVE-2026-87933
DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
| CWE | CWE-416 CWE-119 |
| Vendor | davegamble |
| Product | cjson |
| Published | Sep 10, 2026 |
| Last Updated | Sep 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for davegamble cjson
Be the first to know when new high vulnerabilities affecting davegamble cjson are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
DaveGamble / cJSON
1.7.0 1.7.1 1.7.2 1.7.3 1.7.4 1.7.5 1.7.6 1.7.7 1.7.8 1.7.9 1.7.10 1.7.11 1.7.12 1.7.13 1.7.14 1.7.15 1.7.16 1.7.17 1.7.18 1.7.19
References
vuldb.com: https://vuldb.com/vuln/401815 vuldb.com: https://vuldb.com/vuln/401815/cti vuldb.com: https://vuldb.com/cve/CVE-2026-87933 vuldb.com: https://vuldb.com/submit/911136 github.com: https://github.com/DaveGamble/cJSON/issues/1060 github.com: https://github.com/DaveGamble/cJSON/pull/1065 github.com: https://github.com/DaveGamble/cJSON/
Credits
๐ lrrh (VulDB User) VulDB CNA Team