CVE-2023-26819

EUVD-2023-30611
cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.9 LOW
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 12.53%
Affected Products (NVD)
VendorProductVersion
cjson_projectcjson
1.7.15
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cjson
bookworm
1.7.15-1+deb12u4
fixed
bookworm (security)
1.7.15-1+deb12u4
fixed
bullseye
vulnerable
bullseye (security)
1.7.14-1+deb11u3
fixed
forky
1.7.19-2
fixed
sid
1.7.19-2
fixed
trixie
1.7.18-3.1+deb13u1
fixed
trixie (security)
1.7.18-3.1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cjson
focal
Fixed 1.7.10-1.1ubuntu0.1~esm1
released
jammy
Fixed 1.7.15-1ubuntu0.1
released
noble
Fixed 1.7.17-1ubuntu0.1~esm3
released
oracular
ignored
plucky
ignored
questing
not-affected
resolute
not-affected
Azure Linux logo
Azure Linux Releases
Azure Package
Release
libglvnd
Azure Linux 3.0
0:1.7.0-3.azl3
fixed