Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 29 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jul 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully validated, so the target document is mutated while cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() returns a failure status. An attacker who can supply the patch document can destroy addressable members of the target document even though the API reports that the patch failed, defeating the all-or-nothing behavior callers rely on to reject bad patches. | |
| Title | cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation | |
| First Time appeared |
Davegamble
Davegamble cjson |
|
| Weaknesses | CWE-696 | |
| CPEs | cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Davegamble
Davegamble cjson |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-29T14:45:59.768Z
Reserved: 2026-07-28T19:20:19.157Z
Link: CVE-2026-67217
Updated: 2026-07-29T14:45:33.558Z
No data.
No data.
OpenCVE Enrichment
No data.