CVE-2026-29975
概要

lwjson 1.8.1 contains an improper input validation vulnerability in the streaming JSON parser (lwjson_stream.c). The end-of-string detection logic incorrectly identifies escaped quote characters by only checking the immediately preceding character rather than counting consecutive backslashes, causing valid JSON strings ending with an escaped backslash (like "\\") to never terminate parsing. A remote attacker can send well-formed JSON to cause applications using lwjson_stream_parse() to hang indefinitely, resulting in denial of service.

公表日 2026年5月9日1:16
登録日 2026年5月9日4:15
最終更新日 2026年5月9日1:16
関連情報、対策とツール
共通脆弱性一覧