CVE-2026-16554
published 2026-07-27CVE-2026-16554: cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit…
PriorityP425medium5.1CVSS 4.0
AVLACLATNPRNUINVCNVINVALSCLSILSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based on an underestimated length. When cJSON_PrintBuffered() is used with a pre-allocated buffer, the subsequent write loop overflows the heap allocation. An attacker supplying a crafted JSON string to an application using cJSON on a 32-bit platform can cause a heap buffer overflow, potentially leading to remote code execution, information disclosure, or denial of service.
Because project creator contact attempts were unsuccessful, the vulnerability has only been confirmed in version 1.7.19 but may also affect other versions.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| davegamble | cjson | — | — |
CVSS provenance
nvdv4.05.1MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-16554 86box: cJSON: Remote code execution due to integer overflow via crafted JSON [fedora-all]
bugzilla·2026-07-27·CVSS 5.1
CVE-2026-16554 [MEDIUM] CVE-2026-16554 86box: cJSON: Remote code execution due to integer overflow via crafted JSON [fedora-all]
CVE-2026-16554 86box: cJSON: Remote code execution due to integer overflow via crafted JSON [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based on an underestimated length. When cJSON_PrintBuffered() is used with a pre-allocated buffer, the subsequent write loop overflows the heap allocation.
Bugzilla
CVE-2026-16554 cJSON: cJSON: Remote code execution due to integer overflow via crafted JSON
bugzilla·2026-07-27·CVSS 5.1
CVE-2026-16554 [MEDIUM] CVE-2026-16554 cJSON: cJSON: Remote code execution due to integer overflow via crafted JSON
CVE-2026-16554 cJSON: cJSON: Remote code execution due to integer overflow via crafted JSON
cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based on an underestimated length. When cJSON_PrintBuffered() is used with a pre-allocated buffer, the subsequent write loop overflows the heap allocation. An attacker supplying a crafted JSON string to an application using cJSON on a 32-bit platform can cause a heap buffer overflow, potentially leading to remote code execution, information disclosure, or denial of service.
Because project
Bugzilla
CVE-2026-16554 mmc: cJSON: Remote code execution due to integer overflow via crafted JSON [fedora-all]
bugzilla·2026-07-27·CVSS 5.1
CVE-2026-16554 [MEDIUM] CVE-2026-16554 mmc: cJSON: Remote code execution due to integer overflow via crafted JSON [fedora-all]
CVE-2026-16554 mmc: cJSON: Remote code execution due to integer overflow via crafted JSON [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based on an underestimated length. When cJSON_PrintBuffered() is used with a pre-allocated buffer, the subsequent write loop overflows the heap allocation. An
Bugzilla
CVE-2026-16554 dcm2niix: cJSON: Remote code execution due to integer overflow via crafted JSON [fedora-all]
bugzilla·2026-07-27·CVSS 5.1
CVE-2026-16554 [MEDIUM] CVE-2026-16554 dcm2niix: cJSON: Remote code execution due to integer overflow via crafted JSON [fedora-all]
CVE-2026-16554 dcm2niix: cJSON: Remote code execution due to integer overflow via crafted JSON [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based on an underestimated length. When cJSON_PrintBuffered() is used with a pre-allocated buffer, the subsequent write loop overflows the heap allocatio
Bugzilla
CVE-2026-16554 cjson: cJSON: Remote code execution due to integer overflow via crafted JSON [fedora-all]
bugzilla·2026-07-27·CVSS 5.1
CVE-2026-16554 [MEDIUM] CVE-2026-16554 cjson: cJSON: Remote code execution due to integer overflow via crafted JSON [fedora-all]
CVE-2026-16554 cjson: cJSON: Remote code execution due to integer overflow via crafted JSON [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based on an underestimated length. When cJSON_PrintBuffered() is used with a pre-allocated buffer, the subsequent write loop overflows the heap allocation.
2026-07-27
Published