simdjson CVE-2026-8295 integer overflow fixed
An integer overflow in simdjson library allows buffer miscalculation on 32-bit systems, potentially causing information disclosure or memory corruption; patched in version 4.6.4.
CERT Polska coordinated disclosure of CVE-2026-8295, an integer overflow vulnerability in the simdjson document-builder API. The flaw affects the string_builder::escape_and_append() function when processing very large input strings on platforms with limited size_t width, particularly 32-bit builds. The overflow causes incorrect buffer size calculations, leading to insufficient buffer allocation.
The vulnerability can trigger out-of-bounds memory reads in SIMD routines, with potential impacts including information disclosure, memory corruption, or malformed JSON output. The issue has been addressed in simdjson release 4.6.4.
The vulnerability was responsibly reported by researchers Michał Majchrowicz and Marcin Wyczechowski from AFINE and coordinated through CERT Polska's coordinated vulnerability disclosure process.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8295
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free