cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.
References
Configurations
History
03 Nov 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2025-09-03 15:15
Updated : 2025-11-03 19:16
NVD link : CVE-2025-57052
Mitre link : CVE-2025-57052
CVE.ORG link : CVE-2025-57052
JSON object : View
Products Affected
davegamble
- cjson
