CVE-2025-57052

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
03/09/2025
Last modified:
08/09/2025

Description

cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:* 1.5.0 (including) 1.7.18 (including)


References to Advisories, Solutions, and Tools