Input validation error in cJSON - CVE-2023-26819

 

Input validation error in cJSON - CVE-2023-26819

Published: August 21, 2025


Vulnerability identifier: #VU114342
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-26819
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted document to the application and perform a denial of service (DoS) attack.


Affected software

cJSON
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15
Fedora
openEuler
cjson-debuginfo
cjson-devel
cjson-debugsource
cjson
libcjson1-debuginfo
cJSON-debugsource
libcjson1

How to mitigate CVE-2023-26819

Install updates from vendor's website.

cJSON - update to 1.7.16
cjson-debuginfo - addressed in versions 1.7.15-6, 1.7.15-10
cjson-devel - addressed in versions 1.7.15-6, 1.7.15-10
cjson-debugsource - addressed in versions 1.7.15-6, 1.7.15-10
cjson - addressed in versions 1.7.15-6, 1.7.15-10
cjson - addressed in versions 1.7.19-1.el10_3, 1.7.19-1.fc44
libcjson1-debuginfo - update to 1.7.19-150700.3.3.1
cJSON-debugsource - update to 1.7.19-150700.3.3.1
libcjson1 - update to 1.7.19-150700.3.3.1

External References

Related Security Bulletins