CVE-2023-26819 — Expected Behavior Violation in Cjson
Severity
2.9LOWNVD
EPSS
0.1%
top 71.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 19
Latest updateJan 23
Description
cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 1.4 | Impact: 1.4
Affected Packages9 packages
🔴Vulnerability Details
3📋Vendor Advisories
4Microsoft▶
cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.↗2025-04-08
Debian▶
CVE-2023-26819: cjson - cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as...↗2023