{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "2.3.6"
              },
              {
                "introduced": "3.1.2"
              },
              {
                "fixed": "3.4.1"
              },
              {
                "introduced": "4.0.0"
              },
              {
                "fixed": "4.9.0"
              }
            ],
            "source": "AFFECTED_FIELD"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "9aad59076b0d887cf100cb374a9526a069b69ae4"
            },
            {
              "fixed": "4aaefcec11560cdedd6e975773c14c1b799ae2d6"
            },
            {
              "fixed": "6dd91c6c273a9bd55d927280d71e13fec9ccaf33"
            }
          ],
          "repo": "https://github.com/cedar-policy/cedar-java",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-93g4-m6xv-cmvr"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-843"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55772.json"
  },
  "details": "CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, under certain circumstances, improper input handling could allow Record-to-Entity type confusion across the Java-Rust FFI boundary. CedarJava sends authorization requests to the Rust cedar-policy evaluator as JSON. The JSON protocol reserves magic single-key object shapes (__entity and __extn) for entity references and extension values. When serializing a CedarMap, there is no validation preventing these reserved keys from being used. If an integrating service builds a CedarMap from caller-supplied key/value data (such as request headers, user-defined metadata, or resource tags), an actor who controls those keys could cause the Rust evaluator to interpret a record as an entity reference. This issue requires the integrating service to build a CedarMap where the an actor controls the keys, and a policy must reference that value in a when/unless clause. This vulnerability has been fixed in versions 2.3.6, 3.4.1, and 4.9.",
  "id": "CVE-2026-55772",
  "modified": "2026-07-23T03:56:05.666593412Z",
  "published": "2026-07-13T18:44:47.577Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55772.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/cedar-policy/cedar-java/security/advisories/GHSA-93g4-m6xv-cmvr"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55772"
    }
  ],
  "schema_version": "1.8.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "CedarJava has a type confusion vulnerability"
}