Product
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved reference vulnerability in cJSON_Utils that allows unauthenticated attackers to manipulate JSON object keys via crafted RFC 6902 JSON Pointer escape sequences.