Bug 2508418 (CVE-2026-67216) - CVE-2026-67216 cJSON: Denial of Service due to inefficient JSON object comparison
Summary: CVE-2026-67216 cJSON: Denial of Service due to inefficient JSON object compar...
Keywords:
Status: NEW
Alias: CVE-2026-67216
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-29 14:02 UTC by OSIDB Bzimport
Modified: 2026-07-29 20:05 UTC (History)
15 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-29 14:02:19 UTC
cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred bytes (depth around 40) compared for equality consumes hours of CPU, and the cost roughly doubles with each additional level of nesting. An application that calls cJSON_Compare() on attacker-influenced JSON that is structurally equal to a reference document is exposed to a denial-of-service condition.


Note You need to log in before you can comment on or make changes to this bug.