From 10d36d3af26216050ae43c494fc58e9755c55344 Mon Sep 17 00:00:00 2001 From: Niels Lohmann Date: Sat, 10 Oct 2026 22:25:38 +0200 Subject: [PATCH] Read the node array base after emit() in the view builder's open() emit() moves the node array when it grows, and the subtraction read base in the same expression, so the order was unspecified. MSVC Release builds without forced inlining read the old base; the container index then pointed outside the array and close() wrote out of bounds. Signed-off-by: Niels Lohmann --- include/nlohmann/detail/view/builder.hpp | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/include/nlohmann/detail/view/builder.hpp b/include/nlohmann/detail/view/builder.hpp index ccb54c3d7..6bd48943c 100644 --- a/include/nlohmann/detail/view/builder.hpp +++ b/include/nlohmann/detail/view/builder.hpp @@ -821,7 +821,10 @@ indent_done: NLOHMANN_VIEW_ALWAYS_INLINE void open(value_t k) { - const auto idx = static_cast(emit(k, 0, 0, static_cast(p - b), 0) - base); + // (base is read after emit(), which moves the node array when it + // grows; in one expression the order of the two is unspecified) + const node* const n = emit(k, 0, 0, static_cast(p - b), 0); + const auto idx = static_cast(n - base); if (depth != 0) { const frame f = {cur_idx, cur_count, cur_is_object};