Out-of-Bounds Read Vulnerability in simdjson by Intel
CVE-2026-88358

6.5MEDIUM

Key Information:

Vendor

Intel

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-88358?

The vulnerability in simdjson 4.6.1 involves an out-of-bounds read in the function dom::parser::parse_unpadded(). When processing a specially crafted truncated JSON document, the function may access memory beyond the allocated buffer, particularly after the input buffer is exhausted. This condition is triggered when the document's closing token unexpectedly finalizes a nested structure, leading to an out-of-bounds read in json_iterator::walk_document(). Such access can result in severe outcomes, including application crashes and potential denial of service.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.