在 java-json-tools 的 json-patch 组件(版本 1.13 及以下)中发现了一个漏洞。该漏洞影响了位于文件 中 函数,属于“补丁操作处理器”(Patch Operation Handler)组件。通过操纵该函数可引发资源过度消耗。攻击者可以远程发起此攻击。该漏洞的利用方式已公开披露,可能被用于攻击。项目方已提前通过问题报告得知此问题,但尚未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| java-json-tools | json-patch | 1.0 |
affected |
1.1 |
affected | ||
1.2 |
affected | ||
1.3 |
affected | ||
1.4 |
affected | ||
1.5 |
affected | ||
1.6 |
affected | ||
1.7 |
affected | ||
| … +6 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| java-json-tools | json-patch | 1.0 |
cpe:2.3:a:java-json-tools:json-patch:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86318 | 5.3 MEDIUM | java-json-tools json-patch JsonMergePatchDeserializer.java JsonMergePatch.fromJson stack-b |
| CVE-2026-86321 | 5.3 MEDIUM | java-json-tools jackson-coreutils URL Validation JsonLoader.java JsonLoader.fromURL server |
No comments yet