Skip to content
VulniPulse
Advisory severityMedium5.3Red Hat Linux

Medium [CVE-2026-86319] java-json-tools json-patch: Resource Consumption Vulnerability

This medium-severity Red Hat Linux advisory covers CVE-2026-86319 affecting Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-86319 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch Operation Handler.

The manipulation leads to resource consumption. It is possible to initiate the attack remotely.

The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

By manipulating input, an attacker can cause excessive resource consumption, leading to a Denial of Service (DoS) condition.

An attacker can craft a malicious JSON Patch document containing deeply nested structures, excessively large arrays, or recursive references that cause the parser to enter an infinite loop or allocate memory exponentially, leading to CPU or memory exhaustion and denial of service.

This vulnerability can be exploited remotely and does not require authentication. As of September 2026, the project maintainers have not responded to vulnerability reports and no patch is currently available.

This issue affects Red Hat products that bundle vulnerable versions of json-patch. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

Weakness: CWE-606.

Affected versions
  • 1.13

Official advisory · high-confidence parse· fetched 11 days ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · high-confidence parse· fetched 11 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • There is no official patch available for this vulnerability. Until a fix is released, administrators can implement the following mitigations to reduce the risk of resource exhaustion attacks: 1. Implement strict input validation on JSON Patch documents before passing them to JsonPatch.apply(), including maximum depth limits for nested objects (e.g., depth <= 10), maximum array size limits (e.g., array length <= 1000), and maximum total document size (e.g., <= 100KB). 2. Set timeouts on JSON Patch parsing and application operations to prevent indefinite execution. Implement circuit breakers that abort processing if execution time exceeds reasonable thresholds (e.g., 5 seconds). 3. Apply rate limiting on API endpoints or services that accept JSON Patch documents to prevent rapid repeated attacks from a single source. 4. Configure resource limits (memory, CPU) for Java processes that use json-patch to prevent a single request from consuming all system resources. 5. Where possible, restrict JSON Patch processing to authenticated and trusted sources only. Avoid exposing json-patch functionality directly to unauthenticated external users. 6. Monitor application logs and metrics for unusual resource consumption patterns that may indicate exploitation attempts. Continue to monitor for updates from the json-patch project maintainers and apply patches when they become available.

Official advisory · high-confidence parse· fetched 11 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.