- Sources: write-up, HN 49061790
- Summary: A post dated 2026-07-25 by Joshua Rogers lists 33 defects in the cJSON parser. The author states that every issue affects all versions up to and including v1.7.19 and remains in current code, so there is no fixed release to upgrade to. The first thirteen findings are memory-safety issues and a denial of service, and the rest are logic bugs in JSON Patch handling. The author states development has been stagnant for about four years, that several issues were reported before with proofs of concept, and that some unmerged patches in the repository introduce fresh bugs. The author discloses using AI assistance for the search and the write-up.
- Why it matters: cJSON is vendored into ESP-IDF and a large amount of embedded and server-side C, and with no upgrade path the only stated remediation is to stop parsing untrusted JSON with it.
- Follow-up: Watch for CVE assignments, a maintainer response, and whether any fixed release ships.
send feedback on this story