CVE-2025-57052: Davegamble Cjson
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.
Affected products
- Davegamble Cjson: from 1.5.0, up to and including 1.7.18
Published 2025-09-03. Last modified 2026-06-17.