CVE-2023-26819Expected Behavior Violation in Cjson

Severity
2.9LOWNVD
EPSS
0.1%
top 71.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 19
Latest updateJan 23

Description

cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 1.4 | Impact: 1.4

Affected Packages9 packages

debiandebian/cjson< cjson 1.7.15-1+deb12u3 (bookworm)
Debiancjson_project/cjson< 1.7.14-1+deb11u2+3
Ubuntucjson_project/cjson< 1.7.15-1ubuntu0.1+3

🔴Vulnerability Details

3
OSV
cjson vulnerabilities2026-01-23
GHSA
GHSA-whx8-2789-8w4w: cJSON 12025-04-20
OSV
CVE-2023-26819: cJSON 12025-04-19

📋Vendor Advisories

4
Ubuntu
cJSON vulnerabilities2026-01-23
Red Hat
cJSON: cJSON rejects a valid text2025-04-19
Microsoft
cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.2025-04-08
Debian
CVE-2023-26819: cjson - cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as...2023
CVE-2023-26819 — Expected Behavior Violation in Cjson | cvebase