#1149958 cjson: CVE-2026-87933

Package:
src:cjson
Source:
src:cjson
Submitter:
Salvatore Bonaccorso
Date:
2026-10-08 17:39:06 UTC
Severity:
normal
Tags:
#1149958#5
Date:
2026-10-04 19:04:50 UTC
From:
To:
Hi,

The following vulnerability was published for cjson.

CVE-2026-87933[0]:
| A vulnerability was found in DaveGamble cJSON up to 1.7.19. The
| affected element is the function cJSONUtils_MergePatch of the file
| cJSON_Utils.c. The manipulation results in use after free. The
| attack may be launched remotely. The exploit has been made public
| and could be used. The pull request to fix this issue awaits
| acceptance.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-87933
https://www.cve.org/CVERecord?id=CVE-2026-87933
[1] https://github.com/DaveGamble/cJSON/issues/1060
[2] https://github.com/DaveGamble/cJSON/pull/1065
[3] https://github.com/DaveGamble/cJSON/commit/6d9f2443ab071f86e5d9b43025a40929ec41c46c

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore