VORANT. Threat Intelligence Sign in Get the full feed

simdjson CVE-2026-8295 integer overflow fixed

medium vulnerability

An integer overflow in simdjson library allows buffer miscalculation on 32-bit systems, potentially causing information disclosure or memory corruption; patched in version 4.6.4.

CERT Polska coordinated disclosure of CVE-2026-8295, an integer overflow vulnerability in the simdjson document-builder API. The flaw affects the string_builder::escape_and_append() function when processing very large input strings on platforms with limited size_t width, particularly 32-bit builds. The overflow causes incorrect buffer size calculations, leading to insufficient buffer allocation.

The vulnerability can trigger out-of-bounds memory reads in SIMD routines, with potential impacts including information disclosure, memory corruption, or malformed JSON output. The issue has been addressed in simdjson release 4.6.4.

The vulnerability was responsibly reported by researchers Michał Majchrowicz and Marcin Wyczechowski from AFINE and coordinated through CERT Polska's coordinated vulnerability disclosure process.

Mentioned in this report

Vulnerabilities CVE-2026-8295

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8295

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free