CVE-2021-31875 describes an off-by-one heap-based buffer overflow in the mjs_json_parse function of Cesanta MongooseOS mJS 1.26, triggered by a maliciously crafted JSON string. This critical vulnerability (CVSS 9.8) allows for potential redirection of control flow, with high impacts on confidentiality, integrity, and availability, and can be exploited remotely without authentication or user interaction. Despite its high severity, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion, though the original reporter disputes its practical exploitability for information leaks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.26CPE matchmatch criteria | cpe:2.3:a:cesanta:mongooseos_mjs:1.26:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.