{"id":"CVE-2026-88358","details":"simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded(). A specially crafted truncated JSON document whose final structural token closes a nested array or object can cause json_iterator::walk_document() to access buf[len] after the input buffer has been exhausted. This results in a heap out-of-bounds read and may cause application termination, leading to denial of service.","modified":"2026-09-26T08:04:17.658243Z","published":"2026-09-24T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88358.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88358.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88358"},{"type":"REPORT","url":"https://github.com/simdjson/simdjson/issues/2815"},{"type":"FIX","url":"https://github.com/simdjson/simdjson/commit/20b28712ffce8320237b75a587d35a2e89140577"},{"type":"FIX","url":"https://github.com/simdjson/simdjson/pull/2817"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/simdjson/simdjson","events":[{"introduced":"0"},{"fixed":"20b28712ffce8320237b75a587d35a2e89140577"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v4.6.1","v4.6.0","v4.5.0","v4.4.2","v4.4.1","v4.4.0","v4.3.1","v4.3.0","v4.2.4","v4.2.3","v4.2.2","v4.2.1","v4.2.0","v4.0.7","v4.0.6","v4.0.5","v4.0.4","v4.0.3","v4.0.2","v4.0.1","v4.0.0","v3.13.0","v3.12.3","v3.12.2","v3.12.1","v3.12.0","v3.11.6","v3.11.5","v3.11.4","v3.11.3","v3.11.2","v3.11.1","v3.11.0","v3.10.1","v3.10.0","v3.9.5","v3.9.4","v3.9.3","v3.9.2","v3.9.1","v3.9.0","v3.8.0","v3.7.1","v3.7.0","v3.6.4","v3.6.3","v3.6.2","v3.6.1","v3.6.0","v3.5.0","v3.4.0","v3.3.0","v3.2.3","v3.2.2","v3.2.1","v3.2.0","v3.1.8","v3.1.7","v3.1.6","v3.1.5","v3.1.4","v3.1.3","v3.1.2","v3.1.1","v3.1.0","3.1.0","v3.0.1","v3.0.0","v2.2.3","v2.2.2","v2.2.1","v2.2.0","v2.1.0","v2.0.4","v2.0.3","v2.0.2","v2.0.1","v2.0.0","v1.1.0","v1.0.2","v1.0.1","v1.0.0","v0.9.1","v0.9.0","v0.8.0","v0.7.0","v0.6.0","v0.5.0","v0.4.6","v0.4.5","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.4.0","v0.3.1","v0.3.0","v0.2.1","v0.2.0","v0.1.2","v0.1.1","v0.1.0","v0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88358.json","vanir_signatures_modified":"2026-09-26T08:04:17Z","vanir_signatures":[{"digest":{"line_hashes":["221803649833453960476142758671696747116","189287906113089438303694835018922872413","176731615684929811177536925557719622954","131635123058214744125911791844344779365","125775819034041095639014898153293003055","64990460152038762429208759659193128560","252915102542975714790383093069330290369"],"threshold":0.9},"id":"CVE-2026-88358-235f9626","signature_type":"Line","signature_version":"v1","source":"https://github.com/simdjson/simdjson/commit/20b28712ffce8320237b75a587d35a2e89140577","target":{"file":"src/generic/stage2/tape_builder.h"},"deprecated":false},{"id":"CVE-2026-88358-29c7b780","signature_type":"Function","signature_version":"v1","source":"https://github.com/simdjson/simdjson/commit/20b28712ffce8320237b75a587d35a2e89140577","target":{"file":"tests/dom/unpadded_tests.cpp","function":"run"},"deprecated":false,"digest":{"function_hash":"314272446449395910762996676078859553933","length":263}},{"id":"CVE-2026-88358-89324466","signature_type":"Line","signature_version":"v1","source":"https://github.com/simdjson/simdjson/commit/20b28712ffce8320237b75a587d35a2e89140577","target":{"file":"tests/dom/unpadded_tests.cpp"},"deprecated":false,"digest":{"line_hashes":["194565675035588771109231848467811232432","335344031334973921379923484328548750471","142320280438604655865446410356581462649","69772791155360322633333664152881165605","196140882651525670794894131413975420162","319637562077163268849763737538159605607","236830543364021419612436062573711875762"],"threshold":0.9}},{"digest":{"line_hashes":["312435825054635991804316033658694452321","253095449800212170918810194019461270630","12374980836113449862356677852155235934","338093339712719004681941362895403010515","292045487854032002344565926464322557591","257465043399228054376809568421895462105","218093064719174879426658778632609062689","321362696170812384387785809660570151525","289425340474098988481797269127747035809","242175597685534904469370094678902656524","132784459435302915769266848954540354013","109360929217814682024547198505640178982","56641897088172693501073952505109362297","98167070543408687364433229498707026211","223378468316745851895781276414071675173","135818256752069294766557581934717388407","156849550075020174922903079554582763197","170279301051040206451586119841322014273","88020004910617352541829337237733522497","66964289525277563175019201853242616234","31441708266536567022358228733690752033","164650214958376723262296769709938103012","11471937979975489156272131408091909449","101294635697468732547417373620237570909","12294648079776049078367285882364802572","339639360041952646021522556840717746824","200707635637534399519404124064337167461","193338327134556369800932910510044702346","98212532149580583431908333323578322705","219727383983726955565072286440117922943","74526998203577827501159304916684909857","231667783046755825147797836861163408089","62576494337263956087151913255026244872","160153805587129979852174845359878532120","246155894951818116609328716725152278877","189250418806728512657807851746230965108","192430285577970558724412559499752771672","105469460554824976934607020263890396075","117945012936107950428569637289421871156","71710211975257247885704593556894721513","333415033386888439651566013665261785419","150548664634314104122053278633085310685","142212651718613328068484749408869550668","53863043524759431914933606683700561692","169488840536745235885458029599644619531","103325765052356853029424335151781306684","74526998203577827501159304916684909857","231667783046755825147797836861163408089","62576494337263956087151913255026244872","160153805587129979852174845359878532120","246155894951818116609328716725152278877","269153345262174377752112929173554517907","334479740075213035797932701046703883862","23393618736141272576519005106942101253","317075247191103342086349912955242564683","62215489188419893966761709067000576864","142256702317723052432751707186775431492","261735564990503687553330872153381463381","219792426512108663315115944655789578950","215536890133342706847193148145373335614","312344768062700738396658131390475593472","231014374223722891185971964034705258426","322808037478589601701500210624804445013","66487916597725044830719743399603962704"],"threshold":0.9},"id":"CVE-2026-88358-97e10543","signature_type":"Line","signature_version":"v1","source":"https://github.com/simdjson/simdjson/commit/20b28712ffce8320237b75a587d35a2e89140577","target":{"file":"src/generic/stage2/json_iterator.h"},"deprecated":false}]}}],"schema_version":"1.9.0"}