---
id: CVE-2026-86319
title: A vulnerability has been found in java-json-tools json-patch up to 1.13
summary: >-
  A vulnerability has been found in java-json-tools json-patch up to 1.13.
  Affected by this vulnerability is the function JsonPatch.apply of the file
  src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch
  Operation Ha…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-400
  - CWE-404
  - CWE-606
vendor: java-json-tools
product: json-patch
affected:
  - json-patch 1.0
  - json-patch 1.1
  - json-patch 1.2
  - json-patch 1.3
  - json-patch 1.4
  - json-patch 1.5
  - json-patch 1.6
  - json-patch 1.7
  - json-patch 1.8
  - json-patch 1.9
  - json-patch 1.10
  - json-patch 1.11
  - json-patch 1.12
  - json-patch 1.13
published: '2026-09-07'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:17:17.203'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86319'
references:
  - url: 'https://github.com/java-json-tools/json-patch/'
    label: cna@vuldb.com
  - url: 'https://github.com/java-json-tools/json-patch/issues/167'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86319'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/908321'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399510'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399510/cti'
    label: cna@vuldb.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86319.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-86319'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2529486'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-86319'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86319'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-09T14:43:07.434521Z'
epss: 0.00701
epssPercentile: 0.51132
ingestedAt: '2026-09-08T15:33:26.978Z'
---

## Overview

A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch Operation Handler. The manipulation leads to resource consumption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, Red Hat build of Quarkus, Red Hat Fuse 7 · no fix planned: Red Hat Fuse 7, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86319.json)
