← Voltar à pesquisa de CVEs

CVE-2026-29975

lwjson

Descrição

lwjson 1.8.1 contains an improper input validation vulnerability in the streaming JSON parser (lwjson_stream.c). The end-of-string detection logic incorrectly identifies escaped quote characters by only checking the immediately preceding character rather than counting consecutive backslashes, causing valid JSON strings ending with an escaped backslash (like -\\-) to never terminate parsing. A remote attacker can send well-formed JSON to cause applications using lwjson_stream_parse() to hang indefinitely, resulting in denial of service.

CVSS 7.5EPSS 0.41700000000000004%Risco 0.78
Ver fonte
Publicação
2026-05-08 16:16:10
Versões afetadas
==1.8.1
Tipo
Package
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H