CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

davegamble

cjson

10 known vulnerabilities · sorted by CVSS score

CVE-2019-11834
CRITICAL9.8

cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.

davegamble / cjson+1
Network
Published May 9, 2019
CVE-2018-1000217
CRITICAL9.8

Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. This attack appear to be exploitable via Depends on how application uses cJSON library. If application provides network interface then can be exploited over a network, otherwise just local.. This vulnerability appears to have been fixed in 1.7.4.

davegamble / cjson
Network
Published Aug 20, 2018
CVE-2016-10749
CRITICAL9.8

parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.

davegamble / cjson
Network
Published Apr 29, 2019
CVE-2019-11835
CRITICAL9.8

cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.

davegamble / cjson+1
Network
Published May 9, 2019
CVE-2025-57052
CRITICAL9.8

cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.

davegamble / cjson
Network
Published Sep 3, 2025
CVE-2018-1000216
HIGH8.8

Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, depending on how cJSON library is used this could be either local or over a network. This vulnerability appears to have been fixed in 1.7.3.

davegamble / cjson
Network
Published Aug 20, 2018
CVE-2023-50472
HIGH7.5

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.

davegamble / cjson
Network
Published Dec 14, 2023
CVE-2019-1010239
HIGH7.5

DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vector is: crafted json file. The fixed version is: 1.7.9 and later.

davegamble / cjson+1
Network
Published Jul 19, 2019
CVE-2023-50471
HIGH7.5

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.

davegamble / cjson
Network
Published Dec 14, 2023
CVE-2018-1000215
HIGH7.5

Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS). This attack appear to be exploitable via If the attacker can force the data to be printed and the system is in low memory it can force a leak of memory. This vulnerability appears to have been fixed in 1.7.7.

davegamble / cjson
Network
Published Aug 20, 2018