2.9

CVE-2023-26819

Exploit
cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cjson ProjectCjson Version1.7.15
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.093
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cve@mitre.org 2.9 1.4 1.4
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-440 Expected Behavior Violation

A feature, API, or function does not perform according to its specification.

https://github.com/boofish/json_bugs/tree/main/cjson
Third Party Advisory
Exploit
https://lists.debian.org/debian-lts-announce/2025/06/msg00014.html