VORANT. Threat Intelligence Sign in Get the full feed

Integer overflow in simdjson library (CVE-2026-8295) allows buffer miscalculation on…

medium vulnerability

Integer overflow in simdjson library (CVE-2026-8295) allows buffer miscalculation on 32-bit platforms, potentially causing out-of-bounds reads and memory corruption.

CERT Polska coordinated disclosure of CVE-2026-8295, an integer overflow vulnerability in the simdjson document-builder API. The flaw occurs in the string_builder::escape_and_append() function when processing very large input strings on platforms with limited size_t width, particularly 32-bit builds. The integer overflow causes incorrect buffer size calculations, leading to insufficient buffer allocation.

The vulnerability can result in out-of-bounds memory reads within SIMD routines, potentially causing information disclosure through memory leakage, memory corruption, or malformed JSON output. The issue has been addressed in simdjson release 4.6.4.

The vulnerability was responsibly reported by researchers Michał Majchrowicz and Marcin Wyczechowski from AFINE. Organizations using simdjson, particularly those running 32-bit builds or processing large JSON documents, should upgrade to version 4.6.4 or later to mitigate this risk.

Mentioned in this report

Vulnerabilities CVE-2026-8295

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8295

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free