Out-of-Bounds Read Vulnerability in simdjson by Intel
CVE-2026-88358
6.5MEDIUM
What is CVE-2026-88358?
The vulnerability in simdjson 4.6.1 involves an out-of-bounds read in the function dom::parser::parse_unpadded(). When processing a specially crafted truncated JSON document, the function may access memory beyond the allocated buffer, particularly after the input buffer is exhausted. This condition is triggered when the document's closing token unexpectedly finalizes a nested structure, leading to an out-of-bounds read in json_iterator::walk_document(). Such access can result in severe outcomes, including application crashes and potential denial of service.