Integer overflow in simdjson library (CVE-2026-8295) allows buffer miscalculation on…
Integer overflow in simdjson library (CVE-2026-8295) allows buffer miscalculation on 32-bit platforms, potentially causing out-of-bounds reads and memory corruption.
CERT Polska coordinated disclosure of CVE-2026-8295, an integer overflow vulnerability in the simdjson document-builder API. The flaw occurs in the string_builder::escape_and_append() function when processing very large input strings on platforms with limited size_t width, particularly 32-bit builds. The integer overflow causes incorrect buffer size calculations, leading to insufficient buffer allocation.
The vulnerability can result in out-of-bounds memory reads within SIMD routines, potentially causing information disclosure through memory leakage, memory corruption, or malformed JSON output. The issue has been addressed in simdjson release 4.6.4.
The vulnerability was responsibly reported by researchers Michał Majchrowicz and Marcin Wyczechowski from AFINE. Organizations using simdjson, particularly those running 32-bit builds or processing large JSON documents, should upgrade to version 4.6.4 or later to mitigate this risk.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8295
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free