Ibireme maintains a narrowly scoped JSON parsing library, yyjson, which despite minimal CVE volume can be significant in contexts where it processes untrusted or dynamically constructed data. The observed vulnerability pattern centers on code injection weaknesses, reflecting the risks inherent to any parser handling serialized or templated input. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ibireme over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25713HIGH yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allo | Feb 29, 2024 | 8.6 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ibireme.
Media articles that mention a CVE ID that affects a product developed by Ibireme — matched by CVE ID, not by vendor name.