Input validation error in cJSON - CVE-2023-26819
Published: August 21, 2025
Vulnerability identifier: #VU114342
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-26819
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted document to the application and perform a denial of service (DoS) attack.
Affected software
cJSON
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15
Fedora
openEuler
cjson-debuginfo
cjson-devel
cjson-debugsource
cjson
libcjson1-debuginfo
cJSON-debugsource
libcjson1
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15
Fedora
openEuler
cjson-debuginfo
cjson-devel
cjson-debugsource
cjson
libcjson1-debuginfo
cJSON-debugsource
libcjson1
How to mitigate CVE-2023-26819
Install updates from vendor's website.
cJSON - update to 1.7.16
cjson-debuginfo - addressed in versions 1.7.15-6, 1.7.15-10
cjson-devel - addressed in versions 1.7.15-6, 1.7.15-10
cjson-debugsource - addressed in versions 1.7.15-6, 1.7.15-10
cjson - addressed in versions 1.7.15-6, 1.7.15-10
cjson - addressed in versions 1.7.19-1.el10_3, 1.7.19-1.fc44
libcjson1-debuginfo - update to 1.7.19-150700.3.3.1
cJSON-debugsource - update to 1.7.19-150700.3.3.1
libcjson1 - update to 1.7.19-150700.3.3.1
cjson-debuginfo - addressed in versions 1.7.15-6, 1.7.15-10
cjson-devel - addressed in versions 1.7.15-6, 1.7.15-10
cjson-debugsource - addressed in versions 1.7.15-6, 1.7.15-10
cjson - addressed in versions 1.7.15-6, 1.7.15-10
cjson - addressed in versions 1.7.19-1.el10_3, 1.7.19-1.fc44
libcjson1-debuginfo - update to 1.7.19-150700.3.3.1
cJSON-debugsource - update to 1.7.19-150700.3.3.1
libcjson1 - update to 1.7.19-150700.3.3.1
External References
Related Security Bulletins
- Deniall of service in cJSON
- openEuler 22.03 LTS SP4 update for cjson
- openEuler 24.03 LTS SP1 update for cjson
- openEuler 24.03 LTS update for cjson
- openEuler 22.03 LTS SP3 update for cjson
- openEuler 24.03 LTS SP2 update for cjson
- SUSE update for cJSON
- Fedora 44 update for cjson
- Fedora EPEL 10.3 update for cjson