A vulnerability labeled as problematic has been found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_ApplyPatches. Such manipulation leads to uncontrolled recursion.

This vulnerability is referenced as CVE-2026-67215. It is possible to launch the attack remotely. No exploit is available.