mirror of
https://github.com/nlohmann/json.git
synced 2026-10-02 22:14:14 +07:00
update() and merge_patch() read their argument while they modify *this. When the argument is *this or a value nested inside *this (for example a subobject returned by operator[]), the modification destroys or relocates the value while it is still being iterated, so the functions read freed memory or dereference invalidated iterators (heap-use-after-free, or an uncaught invalid_iterator.214 for update()). This reproduces with plain std::map-backed json and, for update() on ordered_json, also via reallocation of the underlying vector. A fix would require copying the argument whenever it may alias *this, which cannot be checked in constant time without parent pointers (only available under JSON_DIAGNOSTICS), and would cost an unconditional deep copy per call otherwise. The maintainer decided to document the restriction instead of changing the library. Add a "Notes" section with a "!!! danger" admonition to update.md and merge_patch.md explaining that the argument must not be *this or refer into *this, and showing the workaround of passing a copy, e.g. j.update(json(j["a"])) and j.merge_patch(json(j)). Fixes #5641. Signed-off-by: Niels Lohmann <mail@nlohmann.me>