parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.
2025-05-23T16:15:22.080
2025-06-16T18:21:16.333
Analyzed
CVSSv3.1: 2.9 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cjson_project | cjson | < 1.7.18 | Yes |