cJSON 1.5.0 through 1.7.18 allows out-of-bounds access...
Critical severity
Unreviewed
Published
Sep 3, 2025
to the GitHub Advisory Database
•
Updated Sep 8, 2025
Description
Published by the National Vulnerability Database
Sep 3, 2025
Published to the GitHub Advisory Database
Sep 3, 2025
Last updated
Sep 8, 2025
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.
References