Vendor
high
advisory
CVE-2026-29036 Incorrectly-Resolved Reference in cJSON
1 CVEcJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved reference vulnerability in cJSON_Utils that allows unauthenticated attackers to manipulate JSON object keys via crafted RFC 6902 JSON Pointer escape sequences.
cJSON
1c
low
advisory
Denial of Service Vulnerability in cJSON Library (CVE-2026-67215)
1 TTP 1 CVECVE-2026-67215 describes a denial-of-service vulnerability in cJSON through version 1.7.19, where an attacker can trigger uncontrolled recursion and stack exhaustion by supplying a crafted RFC 6902 JSON Patch to cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(), leading to process crash.
cJSON <= 1.7.19
denial-of-service
vulnerability
cJSON
1t
1c