Impact
The vulnerability resides in the cJSONUtils_MergePatch function within DaveGamble's cJSON library. When a crafted JSON input is processed, the function frees memory and then attempts to access that freed memory, creating a use‑after‑free condition. This can lead to memory corruption, application crashes, or potentially unintended execution of code, though the CVE description does not confirm arbitrary code execution.
Affected Systems
All released versions of DaveGamble cJSON from the initial release through version 1.7.19 are affected. Versions beyond 1.7.19 have not been verified to contain the fix and should be considered at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 6.9 signals moderate severity, the EPSS score of less than 1% indicates low exposure probability, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the exploit is public and can be triggered over a remote interface, which raises the potential risk for any system that uses an unpatched copy of the library.
OpenCVE Enrichment