CVE-2016-10749: Davegamble Cjson

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.

Affected products

Published 2019-04-29. Last modified 2026-06-17.