Source: cjson
Version: 1.7.19-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for cjson.

CVE-2026-29036[0]:
| cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved
| name or reference vulnerability in the decode_pointer_inplace()
| function within cJSON_Utils.c that allows unauthenticated attackers
| to cause JSON Patch operations to target wrong object keys by
| supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch
| paths. Attackers can submit malicious RFC 6902 JSON Patch input to
| applications using cJSONUtils_ApplyPatches() or
| cJSONUtils_ApplyPatchesCaseSensitive() to silently corrupt data or
| delete unintended keys, potentially bypassing authorization controls
| in applications that rely on JSON Patch for access-controlled data
| modification.

Can you please check for a respective upstream report and report back?


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-29036
    https://www.cve.org/CVERecord?id=CVE-2026-29036

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to