CVE-2026-86318Medium· 5.3▾ TwilightPoC availableA flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack ma…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.2 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86512Medium· 6.3A vulnerability was identified in java-json-tools json-patch up to 1.13
CVE-2026-86319Medium· 5.3A vulnerability has been found in java-json-tools json-patch up to 1.13
CVE-2026-65338Medium· 4.3The issue was addressed with improved memory handling
CVE-2026-65334Medium· 4.3A memory corruption issue was addressed with improved state management
CVE-2026-65335Medium· 4.3This issue was addressed through improved state management
CVE-2026-65341Medium· 5.4The issue was addressed with improved memory handling