Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-53154

17
FAUCET Score

CVE-2023-53154 is a heap-based buffer over-read vulnerability affecting cJSON versions prior to 1.7.18, specifically within the parse_string function when cJSON_ParseWithLength is used without a trailing newline. This medium-severity vulnerability (CVSS 5.5) can lead to a denial of service (availability impact) through local, low-complexity attacks requiring low privileges. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 1.7.18CPE match
cpe:2.3:a:cjson_project:cjson:*:*:*:*:*:*:*:*
< 1.7.18CPE matchmatch criteria
cpe:2.3:a:cjson_project:cjson:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

2.9LOW

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
1.4
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
13.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 61st percentile among its peer group of 15,938 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

microsoftpatch availablevia msrc
Product: azl3 apparmor 3.1.7-1 on Azure Linux 3.0Fixed in: 3.1.7-1
microsoftpatch availablevia msrc
Product: 20386-17086Fixed in: 3.0.4-5
microsoftpatch availablevia msrc
Product: 20442-17084Fixed in: 3.1.7-1
microsoftpatch availablevia msrc
Product: cbl2 apparmor 3.0.4-4 on CBL Mariner 2.0Fixed in: 3.0.4-5
microsoftpatch availablevia msrc
Product: cbl2 apparmor 3.0.4-5 on CBL Mariner 2.0Fixed in: 3.0.4-5
microsoftpatch availablevia msrc
Product: 20097-17086Fixed in: 3.0.4-5
github_advisoryvendor investigatingvia nvd_reference
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Satellite 6Fixed in: cjson
redhatvendor investigatingvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite-capsule:el8/cjson
redhatvendor investigatingvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite:el8/cjson

Vendor Advisories (2)

redhatCVE-2023-53154Low

cjson: Heap based buffer overflow at cJSON_ParseWithLength function

May 23, 2025
microsoft2025-May/CVE-2023-53154

parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no trailing newline if cJSON_ParseWithLength is called.

May 13, 2025

References

lists.debian.org / debian-lts-announce/2025/06/msg00014.html
github.com / DaveGamble/cJSON/compare/v1.7.17...v1.7.18
Release Notes
github.com / DaveGamble/cJSON/issues/800
ExploitIssue TrackingVendor Advisory