Davegamble maintains cJSON, a lightweight JSON-parsing library widely embedded in embedded systems, IoT devices, and server applications where supply-chain reach exceeds its narrow product footprint. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through memory-safety weakness classes including out-of-bounds reads and writes, NULL-pointer dereferences, double-free conditions, and improper exception handling—flaws characteristic of C-based parsing libraries handling untrusted input. Defenders should inventory downstream products that bundle this library, as a single flaw can propagate across a broad ecosystem; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Davegamble over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-57052CRITICAL cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking | Sep 3, 2025 | 9.8 | 33 | NO | NO |
CVE-2019-11835CRITICAL cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments. | May 9, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-11834CRITICAL cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal. | May 9, 2019 | 9.8 | 31 | NO | NO |
CVE-2016-10749CRITICAL parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character. | Apr 29, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-1000217CRITICAL Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. Thi | Aug 20, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-1000216HIGH Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploi | Aug 20, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-1000215HIGH Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS). This attack appear to be exploitable via I | Aug 20, 2018 | 7.5 | 25 | NO | NO |
CVE-2019-1010239HIGH DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The compo | Jul 19, 2019 | 7.5 | 24 | NO | NO |
CVE-2023-50472HIGH cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c. | Dec 14, 2023 | 7.5 | 19 | NO | NO |
CVE-2023-50471HIGH cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c. | Dec 14, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Davegamble.
Media articles that mention a CVE ID that affects a product developed by Davegamble — matched by CVE ID, not by vendor name.