ThreatCluster

Multiple CVEs Discovered in cJSON Leading to Out-of-Bounds Access Vulnerabilities

First seen 18 Feb 2026, 13:23 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Two vulnerabilities in cJSON have been reported, affecting versions 1.5.0 through 1.7.18 and earlier than 1.7.11. CVE-2019-11834 allows out-of-bounds access related to null characters in string literals, while CVE-2025-57052 enables remote attackers to bypass array bounds checking via malformed JSON pointer strings. Both vulnerabilities pose risks to applications utilizing affected cJSON versions.

Timeline

2019-05-09
CVE-2019-11834 published
2025-09-03
CVE-2025-57052 published
2026-02-18
Information published about both CVEs