# simdjson CVE-2026-8295 integer overflow fixed

Published: 2026-05-14 · Severity: medium
Canonical: https://vorant.io/reports/ca6581a5-a676-51d9-b7e7-c1458dd05305/simdjson-cve-2026-8295-integer-overflow-fixed

> An integer overflow in simdjson library allows buffer miscalculation on 32-bit systems, potentially causing information disclosure or memory corruption; patched in version 4.6.4.

CERT Polska coordinated disclosure of CVE-2026-8295, an integer overflow vulnerability in the simdjson document-builder API. The flaw affects the string_builder::escape_and_append() function when processing very large input strings on platforms with limited size_t width, particularly 32-bit builds. The overflow causes incorrect buffer size calculations, leading to insufficient buffer allocation.

The vulnerability can trigger out-of-bounds memory reads in SIMD routines, with potential impacts including information disclosure, memory corruption, or malformed JSON output. The issue has been addressed in simdjson release 4.6.4.

The vulnerability was responsibly reported by researchers Michał Majchrowicz and Marcin Wyczechowski from AFINE and coordinated through CERT Polska's coordinated vulnerability disclosure process.

## Mentioned in this report

- Vulnerabilities: CVE-2026-8295

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8295

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ca6581a5-a676-51d9-b7e7-c1458dd05305/simdjson-cve-2026-8295-integer-overflow-fixed.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
