CVE-2016-4425

MEDIUM

jansson < 2.7 - Denial of Service via Deep Recursion in JSON Parser

Title source: llm
STIX 2.1

Description

Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted JSON data.

References (7)

Core 7
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/05/03/3
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/05/01/5
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/05/02/1
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3577

Scores

CVSS v3 6.5
EPSS 0.0189
EPSS Percentile 76.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-674
Status published
Products (1)
jansson_project/jansson < 2.7
Published May 17, 2016
Tracked Since Feb 18, 2026