GJSON is a narrowly scoped JSON query and manipulation library that achieves notable deployment depth despite a small CVE footprint, making individual disclosures potentially significant to a wide range of downstream applications. Observed weaknesses cluster around array-index validation and resource-consumption handling, reflecting the parsing and traversal demands inherent to a general-purpose JSON utility. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gjson Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42836HIGH GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack. | Oct 22, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-36067HIGH GJSON <=v1.6.5 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a crafted GET call. | Jan 5, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-36066HIGH GJSON <1.6.5 allows attackers to cause a denial of service (remote) via crafted JSON. | Jan 5, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-35380HIGH GJSON before 1.6.4 allows attackers to cause a denial of service via crafted JSON. | Dec 15, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gjson Project.
Media articles that mention a CVE ID that affects a product developed by Gjson Project — matched by CVE ID, not by vendor name.