Multiple CVEs Discovered in cJSON Leading to Out-of-Bounds Access Vulnerabilities
First seen 18 Feb 2026, 13:23 UTC
•
•39
Export
Article Content
Browse articles
Two vulnerabilities in cJSON have been reported, affecting versions 1.5.0 through 1.7.18 and earlier than 1.7.11. CVE-2019-11834 allows out-of-bounds access related to null characters in string literals, while CVE-2025-57052 enables remote attackers to bypass array bounds checking via malformed JSON pointer strings. Both vulnerabilities pose risks to applications utilizing affected cJSON versions.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2019-05-09
CVE-2019-11834 published
2025-09-03
CVE-2025-57052 published
2026-02-18
Information published about both CVEs
More articles in this cluster
Continue Reading
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows
Data Breach at University of Phoenix Due to Oracle EBS Zero-Day Exploit
Clop Hackers Exploit Oracle Zero-Day, Breaching Barts Health NHS and Dartmouth Data
Cisco Secure Email Gateway Targeted by Advanced Persistent Threat
Logitech Confirms Data Breach Linked to Clop Extortion Gang