在 java-json-tools 库的 json-patch 版本(1.13 及之前版本)中发现一个缺陷,影响 文件中的 函数。该缺陷可能导致基于栈的缓冲区溢出。攻击者可通过远程方式利用此漏洞。相关利用方法已公开,并可能被实际用于攻击。项目方已通过问题报告提前获知该问题,但至今尚未回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| java-json-tools | json-patch | 1.0 |
affected |
1.1 |
affected | ||
1.2 |
affected | ||
1.3 |
affected | ||
1.4 |
affected | ||
1.5 |
affected | ||
1.6 |
affected | ||
1.7 |
affected | ||
| … +6 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| java-json-tools | json-patch | 1.0 |
cpe:2.3:a:java-json-tools:json-patch:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86319 | 5.3 MEDIUM | java-json-tools json-patch Patch Operation JsonPatch.java JsonPatch.apply resource consump |
| CVE-2026-86321 | 5.3 MEDIUM | java-json-tools jackson-coreutils URL Validation JsonLoader.java JsonLoader.fromURL server |
No comments yet