cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred bytes (depth around 40) compared for equality consumes hours of CPU, and the cost roughly doubles with each additional level of nesting. An application that calls cJSON_Compare() on attacker-influenced JSON that is structurally equal to a reference document is exposed to a denial-of-service condition.
References
| Link | Resource |
|---|---|
| https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON.c#L3057-L3180 | Patch |
| https://joshua.hu/cjson-json-parser-cve-vulnerabilities | Exploit Press/Media Coverage Third Party Advisory |
| https://www.vulncheck.com/advisories/cjson-cjson-compare-exponential-complexity-denial-of-service | Third Party Advisory |
Configurations
History
04 Aug 2026, 15:05
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON.c#L3057-L3180 - Patch | |
| References | () https://joshua.hu/cjson-json-parser-cve-vulnerabilities - Exploit, Press/Media Coverage, Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/cjson-cjson-compare-exponential-complexity-denial-of-service - Third Party Advisory | |
| CPE | cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:* | |
| First Time |
Davegamble cjson
Davegamble |
29 Jul 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-29 14:16
Updated : 2026-08-04 15:05
NVD link : CVE-2026-67216
Mitre link : CVE-2026-67216
CVE.ORG link : CVE-2026-67216
JSON object : View
Products Affected
davegamble
- cjson
CWE
CWE-407
Inefficient Algorithmic Complexity
