CVE-2026-67216: cJSON cJSON_Compare Exponential Complexity Denial of Service

Published Jul 29, 2026
·
Updated

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSONCompare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred bytes (depth around 40) compared for equality consumes hours of CPU, and the cost roughly doubles with each additional level of nesting. An application that calls cJSONCompare() on attacker-influenced JSON that is structurally equal to a reference document is exposed to a denial-of-service condition.

Affected Software

2 affected components
cJSON cJSON<=1.7.19
DaveGamble cJSON<=1.7.19

Event History

Jul 29, 2026
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-67216?

CVE-2026-67216 has a medium severity score of 5.9.

2

What is the nature of the vulnerability in CVE-2026-67216?

CVE-2026-67216 is an exponential complexity Denial of Service vulnerability in the cJSON library's cJSON_Compare function due to inefficient recursion.

3

How do I fix CVE-2026-67216?

To fix CVE-2026-67216, update cJSON to a version later than 1.7.19 where the vulnerability has been addressed.

4

What impact does CVE-2026-67216 have on applications using cJSON?

CVE-2026-67216 can lead to Denial of Service by exhausting resources when comparing deeply nested JSON objects.

5

Is CVE-2026-67216 easily exploitable?

CVE-2026-67216 is considered easily exploitable if an application relies on comparing untrusted deeply nested JSON documents.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203