CVE-2026-87933
Dashboard / Vulnerabilities / CVE-2026-87933
CVE-2026-87933
Summary: DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free
Details: A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
References: https://github.com/DaveGamble/cJSON/, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87933.json, https://nvd.nist.gov/vuln/detail/CVE-2026-87933, https://vuldb.com/cve/CVE-2026-87933, https://vuldb.com/submit/911136, https://vuldb.com/vuln/401815, https://github.com/DaveGamble/cJSON/issues/1060, https://vuldb.com/vuln/401815/cti, https://github.com/DaveGamble/cJSON/pull/1065
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
