<Vulnerability name="CVE-2026-86318">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-09-07T14:30:14</PublicDate>
    <Bugzilla id="2529484" url="https://bugzilla.redhat.com/show_bug.cgi?id=2529484" xml:lang="en:us">
java-json-tools/json-patch: java-json-tools json-patch: Remote stack-based buffer overflow via JSON manipulation
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-120</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in java-json-tools json-patch. A remote attacker could exploit a stack-based buffer overflow vulnerability in the `JsonMergePatch.fromJson` function by sending specially crafted JSON input. This could lead to a denial of service, making the affected system unavailable.
    </Details>
    <Statement xml:lang="en:us">
A Moderate impact flaw exists in `java-json-tools json-patch` that allows a remote attacker to trigger a stack-based buffer overflow by sending specially crafted JSON input. This vulnerability, for which an exploit has been published, could lead to a denial of service in Red Hat products such as Red Hat Build of Quarkus, Red Hat Build of Keycloak, Red Hat Integration, and Red Hat JBoss Fuse, if they process untrusted JSON data using the affected library.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:apicurio_registry:3">
        <ProductName>Red Hat build of Apicurio Registry 3</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>json-patch</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:debezium:3">
        <ProductName>Red Hat build of Debezium 3</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>json-patch</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:build_keycloak:">
        <ProductName>Red Hat Build of Keycloak</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>json-patch</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:build_keycloak:">
        <ProductName>Red Hat Build of Keycloak</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>keycloak/rhbk-rhel9-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:build_keycloak:">
        <ProductName>Red Hat Build of Keycloak</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhbk/keycloak-rhel9-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:quarkus:3">
        <ProductName>Red Hat build of Quarkus</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>json-patch</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_fuse:7">
        <ProductName>Red Hat Fuse 7</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>json-patch</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-86318
https://nvd.nist.gov/vuln/detail/CVE-2026-86318
https://github.com/java-json-tools/json-patch/
https://github.com/java-json-tools/json-patch/issues/168
https://vuldb.com/cve/CVE-2026-86318
https://vuldb.com/submit/908319
https://vuldb.com/vuln/399509
https://vuldb.com/vuln/399509/cti
    </References>
</Vulnerability>