CVE-2026-87933High· 8.6▾ MidnightPoC availableA flaw was found in DaveGamble cJSON. The `cJSONUtils_MergePatch` function in `cJSON_Utils.c` is vulnerable to a use-after-free error. A remote attacker could exploit this memory corruption vulnerability, potentially leading to information…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 47.3 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the vendor's CSAF advisory record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
Exploit / PoC code exists
7.3 → 8.6
Last analysed / modified upstream
A flaw was found in DaveGamble cJSON. The cJSONUtils_MergePatch function in cJSON_Utils.c is vulnerable to a use-after-free error. A remote attacker could exploit this memory corruption vulnerability, potentially leading to information disclosure, data corruption, or denial of service.
cJSON: cJSON: Memory corruption via use after free in cJSONUtils_MergePatch — rated Important by Red Hat. Released 2026-09-10, updated 2026-09-14.
Affected:
No fix planned:
Not affected:
Affected
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90815Medium· 6.3A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1
CVE-2026-90698Medium· 5.3A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43
CVE-2026-91203Medium· 6.0A flaw was found in cockpit-files
CVE-2026-92747Medium· 5.0A flaw was found in `cockpit-machines`
CVE-2026-93558High· 7.5A flaw was found in Netty's WebSocketServerExtensionHandler
CVE-2026-93578Medium· 5.9A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client