Search CVE reports


Toggle filters

1 – 10 of 20 results


CVE-2026-67217

Medium priority
Needs evaluation

cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved,...

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-67216

Medium priority
Needs evaluation

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the...

4 affected packages

cjson, iperf3, mapcache, sail-ocaml

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Needs evaluation Needs evaluation Needs evaluation Needs evaluation
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mapcache Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
sail-ocaml Needs evaluation Not in release Not in release
Show less packages

CVE-2026-67215

Medium priority
Needs evaluation

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing...

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-16554

Medium priority
Needs evaluation

cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately...

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-57052

Medium priority

Some fixes available 4 of 5

cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON...

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-53154

Medium priority
Fixed

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-26819

Medium priority

Some fixes available 3 of 5

cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Not affected Fixed Fixed Fixed
Show less packages

CVE-2024-31755

Medium priority
Fixed

cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Not affected Fixed Fixed Not affected
Show less packages

CVE-2023-50472

Medium priority

Some fixes available 2 of 3

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Not affected Not affected Fixed Not affected Not in release
Show less packages

CVE-2023-50471

Medium priority

Some fixes available 2 of 3

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.

1 affected package

cjson

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Not affected Not affected Fixed Not affected Not in release
Show less packages