DaveGamble / cJSON
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-87933 | DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free | MEDIUM | 6.9 | Sep 10, 2026 |
| CVE-2026-29036 | cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding | HIGH | 8.7 | Aug 11, 2026 |
| CVE-2026-67217 | cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation | MEDIUM | 6.9 | Jul 29, 2026 |
| CVE-2026-67216 | cJSON cJSON_Compare Exponential Complexity Denial of Service | HIGH | 8.2 | Jul 29, 2026 |
| CVE-2026-67215 | cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion | HIGH | 8.7 | Jul 29, 2026 |
| CVE-2026-16554 | Integer Overflow Leading to Heap Buffer Overflow in cJSON | MEDIUM | 5.1 | Jul 27, 2026 |
| CVE-2025-57052 | cJSON: out-of-bounds access in decode_array_index_from_pointer() in cJSON_Utils.c via crafted JSON pointer strings | CRITICAL | 9.8 | Sep 3, 2025 |
| CVE-2023-50472 | cjson: segmentation violation in function cJSON_SetValuestring | HIGH | 7.5 | Dec 14, 2023 |
| CVE-2023-50471 | cjson: segmentation violation in function cJSON_InsertItemInArray | HIGH | 7.5 | Dec 14, 2023 |
| CVE-2019-1010239 | DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial… | HIGH | 7.5 | Jul 19, 2019 |
| CVE-2019-11835 | cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments. | CRITICAL | 9.8 | May 9, 2019 |
| CVE-2019-11834 | cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal. | CRITICAL | 9.8 | May 9, 2019 |
| CVE-2016-10749 | parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ charact… | CRITICAL | 9.8 | Apr 29, 2019 |
| CVE-2018-1000217 | Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of… | CRITICAL | 9.8 | Aug 20, 2018 |
| CVE-2018-1000216 | Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attac… | HIGH | 8.8 | Aug 20, 2018 |
| CVE-2018-1000215 | Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS). This attack appear to… | HIGH | 7.5 | Aug 20, 2018 |
Showing 1 to 14 of 14 CVEs