CVE-2025-57052
03.09.2025, 15:15
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.Enginsight
Vendor | Product | Version |
---|---|---|
davegamble | cjson | 1.5.0 ≤ 𝑥 ≤ 1.7.18 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration