CVE-2026-86318: java-json-tools json-patch JsonMergePatchDeserializer.java JsonMergePatch.fromJson stack-based overflow
A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
java-json-tools json-patchto a version that resolves this vulnerability.Fixed in 1.13
Event History
Frequently Asked Questions
Which deployments should be prioritized for triage?
Prioritize applications using java-json-tools json-patch version 1.13 or earlier where JsonMergePatch.fromJson can be reached through remotely supplied input.
Does an attacker need credentials or user interaction?
The supplied vector indicates network exploitation with no privileges and no user interaction required.
Is exploit code available?
Yes. The available data states that an exploit has been published and may be used.
Is a fix or temporary workaround identified?
No fixed version or workaround is identified in the supplied data. The project was reportedly notified through an issue report but had not responded.