Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-86319

CVE-2026-86319: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium5.3

    Medium [CVE-2026-86319] java-json-tools json-patch: Resource Consumption Vulnerability

    CVE-2026-86319Source published Source updated

    A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch Operation Handler. The manipulation leads to resource consumption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. By manipulating input, an attacker can cause excessive resource consumption, leading to a Denial of Service (DoS) condition. An attacker can craft a malicious JSON Patch document containing deeply nested structures, excessively large arrays, or recursive references that cause the parser to enter an…

    Affected products in this advisory
    • Red Hat build of Apicurio Registry 3
    • Red Hat build of Debezium 3
    • Red Hat Build of Keycloak
    • Red Hat build of Quarkus

    1 more entries in the full advisory.

    Source-reported affected versions
    • 1.13
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • There is no official patch available for this vulnerability. Until a fix is released, administrators can implement the following mitigations to reduce the risk of resource exhaustion attacks: 1. Implement strict input validation on JSON Patch documents before passing them to JsonPatch.apply(), including maximum depth limits for nested objects (e.g., depth <= 10), maximum array size limits (e.g., array length <= 1000), and maximum total document size (e.g., <= 100KB). 2. Set timeouts on JSON Patch parsing and application operations to prevent indefinite execution. Implement circuit breakers that abort processing if execution time exceeds reasonable thresholds (e.g., 5 seconds). 3. Apply rate limiting on API endpoints or services that accept JSON Patch documents to prevent rapid repeated attacks from a single source. 4. Configure resource limits (memory, CPU) for Java processes that use json-patch to prevent a single request from consuming all system resources. 5. Where possible, restrict JSON Patch processing to authenticated and trusted sources only. Avoid exposing json-patch functionality directly to unauthenticated external users. 6. Monitor application logs and metrics for unusual resource consumption patterns that may indicate exploitation attempts. Continue to monitor for updates from the json-patch project maintainers and apply patches when they become available.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery