CVE-2025-57052 – cJSON JSON Pointer Out-of-Bounds Access

The following table lists the changes that have been made to the
CVE-2025-57052 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Sep. 03, 2025

    Action Type Old Value New Value
    Added Description cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.
    Added Reference https://x-0r.com/posts/cJSON-Array-Index-Parsing-Vulnerability
Share the Post:

Related Posts