Echo: cjson: security update to 1.7.18-3.1+deb13u1+e1

medium Tenable Self-Hosted Container Security Plugin ID 460231

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit
platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings
containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated
based on an underestimated length. When cJSON_PrintBuffered() is used with a pre-allocated buffer, the
subsequent write loop overflows the heap allocation. An attacker supplying a crafted JSON string to an
application using cJSON on a 32-bit platform can cause a heap buffer overflow, potentially leading to
remote code execution, information disclosure, or denial of service. Because project creator contact
attempts were unsuccessful, the vulnerability has only been confirmed in version 1.7.19 but may also
affect other versions. (CVE-2026-16554)

Solution

Update the cjson library and its related packages to version 1.7.18-3.1+deb13u1+e1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-16554

Plugin Details

Severity: Medium

ID: 460231

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.36

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-16554

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 5.1

Threat Score: 1.2

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:L/SI:L/SA:L

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/28/2026

Vulnerability Publication Date: 7/27/2026

Reference Information

CVE: CVE-2026-16554