Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx json parsing may lead to stack exhaustion in an address sanitized (ASAN) build. This issue may lead to Denial of Service if the program using the jsonxx library crashes. This issue exists on the current commit of the jsonxx project and the project itself has been archived. Updates are not expected. Users are advised to find a replacement.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-28531 Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx json parsing may lead to stack exhaustion in an address sanitized (ASAN) build. This issue may lead to Denial of Service if the program using the jsonxx library crashes. This issue exists on the current commit of the jsonxx project and the project itself has been archived. Updates are not expected. Users are advised to find a replacement.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 28 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Hjiang
Hjiang json\+\+
CPEs cpe:2.3:a:json\+\+_project:json\+\+:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:json\+\+_project:json\+\+:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:hjiang:json\+\+:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:hjiang:json\+\+:1.0.1:*:*:*:*:*:*:*
Vendors & Products Json\+\+ Project
Json\+\+ Project json\+\+
Hjiang
Hjiang json\+\+

Wed, 23 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-23T17:48:29.948Z

Reserved: 2022-01-19T00:00:00.000Z

Link: CVE-2022-23460

cve-icon Vulnrichment

Updated: 2024-08-03T03:43:45.993Z

cve-icon NVD

Status : Modified

Published: 2022-08-19T20:15:08.243

Modified: 2025-10-28T16:00:13.997

Link: CVE-2022-23460

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.