Resource Consumption Vulnerability in json-patch by java-json-tools
CVE-2026-86319
Key Information:
- Vendor
Java-json-tools
- Status
- Vendor
- CVE Published:
- 7 September 2026
Badges
What is CVE-2026-86319?
A vulnerability exists within the json-patch component from java-json-tools, specifically in the JsonPatch.apply function located at src/main/java/com/github/fge/jsonpatch/JsonPatch.java. This vulnerability allows for excessive resource consumption, enabling remote attacks that could lead to Denial of Service. The issue was reported early, but there has been no response from the project maintainers regarding a fix. Organizations using this library should be aware of the potential exploit and take the necessary precautions.
Affected Version(s)
json-patch 1.0
json-patch 1.1
json-patch 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
