Jansson Project maintains a lightweight JSON-parsing library widely embedded across applications and services, presenting a supply-chain risk profile where a single parsing flaw can propagate downstream to numerous dependent products. The library's vulnerability surface centers on input-handling weakness classes including improper input validation, out-of-bounds reads, and uncontrolled recursion, which reflect the complexity of safely parsing untrusted JSON structures. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jansson Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4425HIGH Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted JSON data. | May 17, 2016 | 7.5 | 26 | NO | NO |
CVE-2020-36325HIGH An issue was discovered in Jansson through 2.13.1. Due to a parsing error in json_loads, there's an out-of-bounds read-access bug. NOTE: the vendor reports that this only occurs wh | Apr 26, 2021 | 7.5 | 23 | NO | NO |
CVE-2013-6401MEDIUM Jansson, possibly 2.4 and earlier, does not restrict the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU | Mar 21, 2014 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jansson Project.
Media articles that mention a CVE ID that affects a product developed by Jansson Project — matched by CVE ID, not by vendor name.