PT-2026-64863 · Cjson · Cjson

·

CVE-2026-16554

·

Published

2026-07-27

·

Updated

2026-07-31

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cJSON version 1.7.19
Description An integer overflow exists in the print string ptr() function within cJSON.c on 32-bit platforms. The escape characters counter, a 32-bit size t, can wrap around when processing strings containing approximately 858,993,460 or more control characters. This leads to the output buffer being allocated with an underestimated length. When cJSON PrintBuffered() is used with a pre-allocated buffer, the subsequent write loop causes a heap buffer overflow. An attacker can exploit this by providing a crafted JSON string to an application using the library on a 32-bit platform, potentially resulting in remote code execution, information disclosure, or denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-94184
AZL-94244
CVE-2026-16554
ECHO-23C9-2F44-73C2

Affected Products

Cjson