Medium severity5.9NVD Advisory· Published Jul 29, 2026· Updated Aug 4, 2026
CVE-2026-67216
CVE-2026-67216
Description
cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred bytes (depth around 40) compared for equality consumes hours of CPU, and the cost roughly doubles with each additional level of nesting. An application that calls cJSON_Compare() on attacker-influenced JSON that is structurally equal to a reference document is exposed to a denial-of-service condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*range: <=1.7.19
- (no CPE)range: <=1.7.19
Patches
Vulnerability mechanics
References
3- github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON.cnvdPatch
- joshua.hu/cjson-json-parser-cve-vulnerabilitiesnvdExploitPress/Media CoverageThird Party Advisory
- www.vulncheck.com/advisories/cjson-cjson-compare-exponential-complexity-denial-of-servicenvdThird Party Advisory
News mentions
0No linked articles in our index yet.