Impact
armink struct2json 1.0 contains a null pointer dereference in the S2J_STRUCT_GET_string_ELEMENT function when processing a crafted valuestring argument during JSON deserialization. The flaw can be triggered remotely, causing the application to crash and resulting in a denial‑of‑service condition.
Affected Systems
The vulnerability affects the armink struct2json component, specifically version 1.0 as identified by the CNA. It applies to any deployment that uses this version of the library for JSON deserialization operations.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS information is not provided and the vulnerability is not listed in CISA KEV, but the exploit has been publicly disclosed and can be delivered remotely using a crafted JSON payload. Attackers who supply malicious input to applications incorporating this library can cause the target process to crash, potentially impacting availability of services that depend on the deserialization routine. The risk is moderate to high in environments that accept untrusted JSON data from external sources.
OpenCVE Enrichment