CVE-2026-67216
Description
A flaw was found in cJSON. An inefficient algorithmic complexity flaw in the cJSON_Compare() function allows a remote attacker to cause a denial of service (DoS). By providing specially crafted, deeply nested JSON (JavaScript Object Notation) objects for comparison, an attacker can consume excessive CPU resources, leading to the application becoming unresponsive for extended periods.
Statement
While upstream sources rate this flaw as High impact (CVSSv4 8.2), Red Hat evaluates this issue as Moderate impact (CVSS 5.9). This reflects a higher Attack Complexity (AC:H) and an impact strictly isolated to Availability (A:H), with zero effect on Confidentiality or Integrity (C:N, I:N).
Exploitation is narrowly constrained: an attacker cannot trigger resource exhaustion simply by submitting a deeply nested document to a standard JSON ingestion endpoint. The host application must explicitly pass the input into cJSON_Compare() against a structurally matching reference document. Applications that only parse, validate, or serialize JSON without invoking object equality comparisons are completely unaffected by this algorithmic complexity flaw.
When triggered, the resulting exponential running time leads strictly to thread CPU starvation. It does not cause stack exhaustion crashes, memory corruption, or arbitrary code execution.
Mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 5.9 | 7.5 | 5.9 |
| Attack Vector | Network | Network | Network |
| Attack Complexity | High | Low | High |
| Privileges Required | None | None | None |
| User Interaction | None | None | None |
| Scope | Unchanged | Unchanged | Unchanged |
| Confidentiality | None | None | None |
| Integrity Impact | None | None | None |
| Availability Impact | High | High | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cve.org: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)
When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.