Bug 2514418 (CVE-2026-29036)
| Summary: | CVE-2026-29036 cJSON: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | anthomas, ehelms, ggainey, jpasqual, juwatts, mdellweg, mhulan, nmoumoul, osousa, pcreech, rchan, rhel-process-autobot, smallamp, tmalecek, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in cJSON, a JSON parser and generator. This vulnerability allows unauthenticated attackers to manipulate JSON Patch operations by supplying crafted JSON Pointer escape sequences. This can lead to silent corruption of data or the deletion of unintended keys, potentially bypassing authorization controls in applications that use cJSON for data modification. The flaw resides in the `decode_pointer_inplace()` function.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2515200, 2515201 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-08-11 21:51:30 UTC
|