Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 29 Jul 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred bytes (depth around 40) compared for equality consumes hours of CPU, and the cost roughly doubles with each additional level of nesting. An application that calls cJSON_Compare() on attacker-influenced JSON that is structurally equal to a reference document is exposed to a denial-of-service condition. | |
| Title | cJSON cJSON_Compare Exponential Complexity Denial of Service | |
| First Time appeared |
Davegamble
Davegamble cjson |
|
| Weaknesses | CWE-407 | |
| CPEs | cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Davegamble
Davegamble cjson |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-29T16:00:06.548Z
Reserved: 2026-07-28T19:20:19.157Z
Link: CVE-2026-67216
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T15:45:03Z
-
CWE-407
Inefficient Algorithmic Complexity