CVE-2018-17072: Json++ Project Json++
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
JSON++ through 2016-06-15 has a buffer over-read in yyparse() in json.y.
Affected products
- Json++ Project Json++: up to and including 2016-06-15
Published 2018-09-16. Last modified 2026-06-17.