CVE-2026-87933
- EPSS 0.31%
- Veröffentlicht 10.09.2026 00:15:08
- Zuletzt bearbeitet 10.09.2026 20:17:31
A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been ma...
CVE-2026-29036
- EPSS 0.26%
- Veröffentlicht 11.08.2026 21:30:01
- Zuletzt bearbeitet 24.09.2026 20:30:25
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong obj...
CVE-2026-67217
- EPSS 0.25%
- Veröffentlicht 29.07.2026 13:32:04
- Zuletzt bearbeitet 04.08.2026 15:03:41
cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target...
CVE-2026-67216
- EPSS 0.35%
- Veröffentlicht 29.07.2026 13:32:03
- Zuletzt bearbeitet 04.08.2026 15:05:11
cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponentia...
CVE-2026-67215
- EPSS 0.38%
- Veröffentlicht 29.07.2026 13:32:02
- Zuletzt bearbeitet 04.08.2026 15:09:26
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operati...
CVE-2026-16554
- EPSS 0.3%
- Veröffentlicht 27.07.2026 08:40:17
- Zuletzt bearbeitet 26.08.2026 14:22:00
cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more...
CVE-2025-57052
- EPSS 0.74%
- Veröffentlicht 03.09.2025 00:00:00
- Zuletzt bearbeitet 03.11.2025 19:16:12
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containi...
CVE-2023-50471
- EPSS 1.51%
- Veröffentlicht 14.12.2023 20:15:53
- Zuletzt bearbeitet 04.11.2025 22:15:55
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
CVE-2023-50472
- EPSS 0.96%
- Veröffentlicht 14.12.2023 20:15:53
- Zuletzt bearbeitet 22.07.2025 18:17:45
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.
CVE-2019-1010239
- EPSS 2.42%
- Veröffentlicht 19.07.2019 17:15:11
- Zuletzt bearbeitet 22.07.2025 18:17:45
DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vecto...