CVE-2026-6902
published 2026-05-18CVE-2026-6902: A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potential…
PriorityP348high7.7CVSS 4.0
AVNACLATPPRNUIPVCHVIHVAHSCLSILSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.46%
39.4th percentile
A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potential security risks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| perforce | p4 | < P4 (Helix Core) 2025.2 Patch 2 | P4 (Helix Core) 2025.2 Patch 2 |
CVSS provenance
nvdv4.07.7HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Perforce P4 up to 2025.2 Patch 1 code injection (EUVD-2026-30747)
vuldb·2026-05-18·CVSS 7.7
CVE-2026-6902 [HIGH] Perforce P4 up to 2025.2 Patch 1 code injection (EUVD-2026-30747)
A vulnerability, which was classified as critical, was found in Perforce P4 up to 2025.2 Patch 1. Affected by this issue is some unknown functionality. The manipulation results in code injection.
This vulnerability is cataloged as CVE-2026-6902. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
GHSA-9fr9-58h7-gj3c: A vulnerability in Command-Line Client in P4 Server prior to the 2025
ghsa_unreviewed·2026-05-18·CVSS 7.7
CVE-2026-6902 [HIGH] CWE-94 GHSA-9fr9-58h7-gj3c: A vulnerability in Command-Line Client in P4 Server prior to the 2025
A vulnerability in Command-Line Client in P4 Server prior to the 2025.2 Patch 2, identified as CVE-2026-6902, has been fixed in P4 Server to address potential security risks.
Red Hat
cJSON: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding
vendor_redhat·2026-08-11·CVSS 7.5
CVE-2026-29036 [HIGH] CWE-386 cJSON: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding
cJSON: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() to silently corrupt data or delete unintended keys, potentially bypassing authorization controls in applications that rely on JSON Patch for access-controlled data modification.
A flaw was found in cJSON, a JSON parser an
Red Hat
cJSON: cJSON: Data destruction due to non-atomic JSON Patch application
vendor_redhat·2026-07-29·CVSS 5.3
CVE-2026-67217 [MEDIUM] CWE-179 cJSON: cJSON: Data destruction due to non-atomic JSON Patch application
cJSON: cJSON: Data destruction due to non-atomic JSON Patch application
cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully validated, so the target document is mutated while cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() returns a failure status. An attacker who can supply the patch document can destroy addressable members of the target document even though the API reports that the patch failed, defeating the all-or-nothing behavior callers rely on to reject bad patches.
A flaw was found in cJSON. The library a
Red Hat
cJSON: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application
vendor_redhat·2026-07-29·CVSS 7.5
CVE-2026-67215 [HIGH] CWE-770 cJSON: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application
cJSON: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service.
A flaw was found in cJSON. A remote attacker can exploi
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-67215 86box: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [fedora-all]
bugzilla·2026-08-25·CVSS 7.5
CVE-2026-67215 [HIGH] CVE-2026-67215 86box: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [fedora-all]
CVE-2026-67215 86box: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten
Bugzilla
CVE-2026-67215 dcm2niix: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [fedora-all]
bugzilla·2026-08-25·CVSS 7.5
CVE-2026-67215 [HIGH] CVE-2026-67215 dcm2niix: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [fedora-all]
CVE-2026-67215 dcm2niix: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, t
Bugzilla
CVE-2026-67217 mmc: cJSON: Data destruction due to non-atomic JSON Patch application [fedora-all]
bugzilla·2026-08-25·CVSS 5.3
CVE-2026-67217 [MEDIUM] CVE-2026-67217 mmc: cJSON: Data destruction due to non-atomic JSON Patch application [fedora-all]
CVE-2026-67217 mmc: cJSON: Data destruction due to non-atomic JSON Patch application [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully validated, so the target document is mutated while cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() returns a failure status. An attacker who can
Bugzilla
CVE-2026-67215 cjson: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [fedora-all]
bugzilla·2026-08-25·CVSS 7.5
CVE-2026-67215 [HIGH] CVE-2026-67215 cjson: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [fedora-all]
CVE-2026-67215 cjson: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten
Bugzilla
CVE-2026-67215 cjson: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [epel-all]
bugzilla·2026-08-25·CVSS 7.5
CVE-2026-67215 [HIGH] CVE-2026-67215 cjson: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [epel-all]
CVE-2026-67215 cjson: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten ti
Bugzilla
CVE-2026-67215 mmc: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [fedora-all]
bugzilla·2026-08-25·CVSS 7.5
CVE-2026-67215 [HIGH] CVE-2026-67215 mmc: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [fedora-all]
CVE-2026-67215 mmc: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten ti
Bugzilla
CVE-2026-29036 cjson: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding [fedora-all]
bugzilla·2026-08-13·CVSS 7.5
CVE-2026-29036 [HIGH] CVE-2026-29036 cjson: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding [fedora-all]
CVE-2026-29036 cjson: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUti
Bugzilla
CVE-2026-29036 cjson: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding [epel-all]
bugzilla·2026-08-13·CVSS 7.5
CVE-2026-29036 [HIGH] CVE-2026-29036 cjson: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding [epel-all]
CVE-2026-29036 cjson: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUtils
Bugzilla
CVE-2026-29036 cJSON: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding
bugzilla·2026-08-11·CVSS 7.5
CVE-2026-29036 [HIGH] CVE-2026-29036 cJSON: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding
CVE-2026-29036 cJSON: cJSON: Data corruption and unauthorized modification via JSON Pointer escape decoding
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() to silently corrupt data or delete unintended keys, potentially bypassing authorization controls in applications that rely on JSON Patch for access-controlled data modification.
Bugzilla
CVE-2026-67215 cJSON: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application
bugzilla·2026-07-29·CVSS 7.5
CVE-2026-67215 [HIGH] CVE-2026-67215 cJSON: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application
CVE-2026-67215 cJSON: cJSON: Denial of Service via uncontrolled recursion in JSON Patch application
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service.
Bugzilla
CVE-2026-67217 cJSON: cJSON: Data destruction due to non-atomic JSON Patch application
bugzilla·2026-07-29·CVSS 5.3
CVE-2026-67217 [MEDIUM] CVE-2026-67217 cJSON: cJSON: Data destruction due to non-atomic JSON Patch application
CVE-2026-67217 cJSON: cJSON: Data destruction due to non-atomic JSON Patch application
cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully validated, so the target document is mutated while cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() returns a failure status. An attacker who can supply the patch document can destroy addressable members of the target document even though the API reports that the patch failed, defeating the all-or-nothing behavior callers rely on to reject bad patches.
2026-05-18
Published