Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-1000216

27
FAUCET Score

CVE-2018-1000216 is a critical double-free vulnerability (CWE-415) affecting Dave Gamble cJSON library versions 1.7.2 and earlier. This flaw can lead to a denial of service (crash) or potentially remote code execution (RCE). The vulnerability has a CVSSv3 score of 8.8 (High), indicating a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Exploitation requires an attacker to trick a victim into processing malicious JSON data, which could occur locally or over a network depending on the cJSON library's implementation. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.7.3CPE matchmatch criteria
cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.8HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
1.47%
Probability of exploitation in next 30 days
EPSS Percentile
71.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0147 is in the 70th percentile among its peer group of 14,848 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

microsoftpatch availablevia msrc
Product: 16928-16817Fixed in: 1.7.0-2
microsoftpatch availablevia msrc
Product: 16928-17084Fixed in: 1.7.0-2
microsoftpatch availablevia msrc
Product: azl3 libglvnd 1.7.0-2 on Azure Linux 3.0Fixed in: 1.7.0-2

Vendor Advisories (1)

microsoft2018-Aug/CVE-2018-1000216Important

Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, depending on how cJSON library is used this could be either local or over a network. This vulnerability appears to have been fixed in 1.7.3.

Aug 14, 2018

References

github.com / DaveGamble/cJSON/issues/241
ExploitThird Party Advisory