PT-2025-35723 · Cjson+5 · Cjson+5
X-0R
·
Published
2025-09-03
·
Updated
2026-03-11
·
CVE-2025-57052
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
cJSON versions 1.5.0 through 1.7.18
Description
cJSON versions 1.5.0 through 1.7.18 contain an out-of-bounds access issue within the
decode array index from pointer function located in cJSON Utils.c. This allows attackers to bypass array bounds checking and potentially access restricted data by providing malformed JSON pointer strings that include alphanumeric characters.Recommendations
Update cJSON to a version later than 1.7.18.
Exploit
Fix
RCE
Out of bounds Read
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Red Os
Ubuntu
Cjson