java-json-tools json-patch Patch Operation JsonPatch.java JsonPatch.apply resource consumption
Summary
| CVE | CVE-2026-86319 |
|---|---|
| State | PUBLISHED |
| Assigner | VulDB |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-07 15:17:34 UTC |
| Updated | 2026-09-09 15:17:17 UTC |
| Description | A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch Operation Handler. The manipulation leads to resource consumption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. |
Risk And Classification
Primary CVSS: v4.0 5.5 MEDIUM from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.004050000 probability, percentile 0.340060000 (date 2026-09-09)
Problem Types: CWE-400 | CWE-404 | CWE-400 Resource Consumption | CWE-404 Denial of Service
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 5.5 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/C... |
| 4.0 | CNA | DECLARED | 6.9 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P |
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| 3.1 | CNA | DECLARED | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R |
| 3.0 | CNA | DECLARED | 5.3 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R |
| 2.0 | [email protected] | Secondary | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P | |
| 2.0 | CNA | DECLARED | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:UR |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v3.0 Breakdown
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Java-json-tools | Json-patch | affected 1.0 | Not specified |
| CNA | Java-json-tools | Json-patch | affected 1.1 | Not specified |
| CNA | Java-json-tools | Json-patch | affected 1.2 | Not specified |
| CNA | Java-json-tools | Json-patch | affected 1.3 | Not specified |
| CNA | Java-json-tools | Json-patch | affected 1.4 | Not specified |
| CNA | Java-json-tools | Json-patch | affected 1.5 | Not specified |
| CNA | Java-json-tools | Json-patch | affected 1.6 | Not specified |
| CNA | Java-json-tools | Json-patch | affected 1.7 | Not specified |
| CNA | Java-json-tools | Json-patch | affected 1.8 | Not specified |
| CNA | Java-json-tools | Json-patch | affected 1.9 | Not specified |
| CNA | Java-json-tools | Json-patch | affected 1.10 | Not specified |
| CNA | Java-json-tools | Json-patch | affected 1.11 | Not specified |
| CNA | Java-json-tools | Json-patch | affected 1.12 | Not specified |
| CNA | Java-json-tools | Json-patch | affected 1.13 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| vuldb.com/submit/908321 | [email protected] | vuldb.com | |
| vuldb.com/vuln/399510 | [email protected] | vuldb.com | |
| github.com/java-json-tools/json-patch/issues/167 | [email protected] | github.com | |
| vuldb.com/vuln/399510/cti | [email protected] | vuldb.com | |
| github.com/java-json-tools/json-patch | [email protected] | github.com | |
| vuldb.com/cve/CVE-2026-86319 | [email protected] | vuldb.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: York Shen - Yong Shen - PayPal Cyber Security Team (VulDB User) (en)
CNA: VulDB CNA Team (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-09-07T00:00:00.000Z | Advisory disclosed |
| CNA | 2026-09-07T02:00:00.000Z | VulDB entry created |
| CNA | 2026-09-07T07:38:12.000Z | VulDB entry last update |