{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-87933","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-09-09T16:21:04.414Z","datePublished":"2026-09-10T00:15:08.473Z","dateUpdated":"2026-09-10T19:06:09.220Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-09-10T00:15:08.473Z"},"title":"DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-416","lang":"en","description":"Use After Free"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-119","lang":"en","description":"Memory Corruption"}]}],"affected":[{"vendor":"DaveGamble","product":"cJSON","versions":[{"version":"1.7.0","status":"affected"},{"version":"1.7.1","status":"affected"},{"version":"1.7.2","status":"affected"},{"version":"1.7.3","status":"affected"},{"version":"1.7.4","status":"affected"},{"version":"1.7.5","status":"affected"},{"version":"1.7.6","status":"affected"},{"version":"1.7.7","status":"affected"},{"version":"1.7.8","status":"affected"},{"version":"1.7.9","status":"affected"},{"version":"1.7.10","status":"affected"},{"version":"1.7.11","status":"affected"},{"version":"1.7.12","status":"affected"},{"version":"1.7.13","status":"affected"},{"version":"1.7.14","status":"affected"},{"version":"1.7.15","status":"affected"},{"version":"1.7.16","status":"affected"},{"version":"1.7.17","status":"affected"},{"version":"1.7.18","status":"affected"},{"version":"1.7.19","status":"affected"}],"cpes":["cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":6.9,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":7.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"HIGH"}},{"cvssV3_0":{"version":"3.0","baseScore":7.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"HIGH"}},{"cvssV2_0":{"version":"2.0","baseScore":7.5,"vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-09-09T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-09-09T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-09-09T18:26:11.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"lrrh (VulDB User)","type":"reporter"},{"lang":"en","value":"VulDB CNA Team","type":"coordinator"}],"references":[{"url":"https://vuldb.com/vuln/401815","name":"VDB-401815 | DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/401815/cti","name":"VDB-401815 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-87933","name":"CVE-2026-87933 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/911136","name":"Submit #911136 | DaveGamble cJSON v1.7.19 Use After Free","tags":["third-party-advisory"]},{"url":"https://github.com/DaveGamble/cJSON/issues/1060","tags":["exploit","issue-tracking"]},{"url":"https://github.com/DaveGamble/cJSON/pull/1065","tags":["issue-tracking","patch"]},{"url":"https://github.com/DaveGamble/cJSON/","tags":["product"]}],"x_generator":["VulDB PVTS v202609"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-10T17:51:16.285890Z","id":"CVE-2026-87933","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-10T19:06:09.220Z"}}]}}