cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade cjson | Oct 28, 2025 | Sep 3, 2025 |
| Debian | — | Upgrade cjson | Sep 16, 2025 | Sep 16, 2025 |
| Suse | — | Upgrade libcjson1 | Dec 5, 2025 | Oct 10, 2025 |
| Ubuntu | — | Upgrade libcjson1Upgrade libcjson1 (Ubuntu Pro) | Jan 27, 2026 | Sep 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub