Search CVE reports


Toggle filters

1 – 10 of 22 results


CVE-2026-87933

Medium priority
Needs evaluation

A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The...

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-29036

Medium priority
Vulnerable

cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations...

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Vulnerable Vulnerable Vulnerable Vulnerable —
Show less packages

CVE-2026-67217

Medium priority
Vulnerable

cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved,...

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Vulnerable Vulnerable Vulnerable Vulnerable —
Show less packages

CVE-2026-67216

Medium priority
Vulnerable

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the...

4 affected packages

cjson, iperf3, mapcache, sail-ocaml

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Vulnerable Vulnerable Vulnerable Vulnerable —
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mapcache Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
sail-ocaml Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-67215

Medium priority
Vulnerable

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing...

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Vulnerable Vulnerable Vulnerable Vulnerable —
Show less packages

CVE-2026-16554

Medium priority
Vulnerable

cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately...

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Vulnerable Vulnerable Vulnerable Vulnerable —
Show less packages

CVE-2025-57052

Medium priority

Some fixes available 4 of 5

cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON...

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Not affected Fixed Fixed Fixed —
Show less packages

CVE-2023-53154

Medium priority
Fixed

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Not affected Fixed Fixed Fixed —
Show less packages

CVE-2023-26819

Medium priority

Some fixes available 3 of 5

cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Not affected Fixed Fixed Fixed —
Show less packages

CVE-2024-31755

Medium priority
Fixed

cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Not affected Fixed Fixed Not affected —
Show less packages