PT-2025-35723 · Cjson+5 · Cjson+5

·

CVE-2025-57052

·

Published

2025-09-03

·

Updated

2026-03-11

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cJSON versions 1.5.0 through 1.7.18
Description cJSON versions 1.5.0 through 1.7.18 contain an out-of-bounds access issue within the decode array index from pointer function located in cJSON Utils.c. This allows attackers to bypass array bounds checking and potentially access restricted data by providing malformed JSON pointer strings that include alphanumeric characters.
Recommendations Update cJSON to a version later than 1.7.18.

Exploit

Fix

DoS

RCE

Improper Validation of Array Index

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12379
ALT-PU-2025-12381
BDU:2025-12591
CVE-2025-57052
DLA-4304-1
DSA-6001-1
OESA-2025-2374
OESA-2025-2375
OESA-2025-2376
OESA-2025-2377
OESA-2025-2491
OPENSUSE-SU-2025:15583-1
OPENSUSE-SU-2026:20340-1
RHSA-2025:17614
SUSE-SU-2025:03520-1
USN-7973-1

Affected Products

Alt Linux
Debian
Linuxmint
Red Os
Ubuntu
Cjson