AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-57052

CRITICAL · CVSS 9.8 EPSS 0.69%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-09-03 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable.

CVE
CVE-2025-57052
Severity
CRITICAL
CVSS
9.8
EPSS
0.69%

Original NVD Description

cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.

Related CVEs

Other vulnerabilities affecting the same vendor(s)