VYPR

Simdjson

by Simdjson

Source repositories

CVEs (2)

  • CVE-2026-8295MedMay 14, 2026
    risk 0.45cvss —epss 0.00

    An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "string_builder::escape_and_append()" when processing very large input strings on platforms with limited "size_t" width (e.g., 32-bit builds). The overflow can…

  • CVE-2026-88358MedSep 24, 2026
    risk 0.35cvss 6.5epss 0.00

    simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded(). A specially crafted truncated JSON document whose final structural token closes a nested array or object can cause json_iterator::walk_document() to access buf[len] after the…