{"id":"CVE-2026-87933","title":"cJSON: cJSON: Memory corruption via use after free in cJSONUtils_MergePatch (CVE-2026-87933)","summary":"A flaw was found in DaveGamble cJSON. The `cJSONUtils_MergePatch` function in `cJSON_Utils.c` is vulnerable to a use-after-free error. A remote attacker could exploit this memory corruption vulnerability, potentially leading to information…","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L","cvssSource":"vendor","cwe":["CWE-825","CWE-416","CWE-119"],"vendor":"Red Hat","product":"Red Hat Satellite 6","affected":["satellite 6"],"published":"2026-09-10","updated":"2026-09-14","sourceUpdated":"2026-09-14T11:59:02+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87933.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87933.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-87933"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2531215"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-87933"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87933"},{"url":"https://github.com/DaveGamble/cJSON/"},{"url":"https://github.com/DaveGamble/cJSON/issues/1060"},{"url":"https://github.com/DaveGamble/cJSON/pull/1065"},{"url":"https://vuldb.com/cve/CVE-2026-87933"},{"url":"https://vuldb.com/submit/911136"},{"url":"https://vuldb.com/vuln/401815"},{"url":"https://vuldb.com/vuln/401815/cti"}],"tags":["csaf","vex","red-hat","cve.org","exploit-available"],"epss":0.00307,"epssPercentile":0.23618,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-10T17:51:16.285890Z"},"scores":{"vendor":8.6,"cna":7.3},"ingestedAt":"2026-09-11T16:45:48.025Z","slug":"CVE-2026-87933","body":"## Overview\n\nA flaw was found in DaveGamble cJSON. The `cJSONUtils_MergePatch` function in `cJSON_Utils.c` is vulnerable to a use-after-free error. A remote attacker could exploit this memory corruption vulnerability, potentially leading to information disclosure, data corruption, or denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Satellite 6 · no fix planned: Red Hat Satellite 6 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87933.json)\n\n**cJSON: cJSON: Memory corruption via use after free in cJSONUtils_MergePatch** — rated Important by Red Hat. Released 2026-09-10, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Satellite 6\n\nNo fix planned:\n\n- Red Hat Satellite 6\n\nNot affected:\n\n- Red Hat Hardened Images\n\n## Remediation\n\nAffected","depth":"midnight","depthScore":59,"depthScoreParts":{"impact":47.3,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":109125,"id":"CVE-2026-87933","ts":1789183730405,"field":"cvss","old":"7.3","new":"8.6"},{"seq":54182,"id":"CVE-2026-87933","ts":1789070710656,"field":"exploit_available","old":"false","new":"true"}]}