Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted JSON data.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jansson | Aug 30, 2017 | May 17, 2016 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 17, 2016 |
| Debian | — | Upgrade jansson | May 14, 2016 | May 14, 2016 |
| Freebsd | — | Upgrade jansson | Dec 10, 2025 | May 4, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade jansson | Dec 4, 2019 | May 17, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade jansson | Dec 18, 2019 | May 17, 2016 |
| Oracle Solaris | — | Upgrade library/jansson to version 2.7-0.175.3.35.0.3.0 on Solaris 11.3 | Aug 24, 2018 | May 17, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 1, 2016 |
| Ubuntu | — | Upgrade jansson | Nov 19, 2024 | May 17, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub