A vulnerability labeled as problematic has been found in DaveGamble cJSON up to 1.7.19. The affected element is the function
cJSONUtils_ApplyPatches. Such manipulation leads to uncontrolled recursion.
This vulnerability is referenced as CVE-2026-67215. It is possible to launch the attack remotely. No exploit is available.