{"id":"CVE-2021-31875","details":"In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_json_parse, which can potentially lead to redirection of control flow. NOTE: the original reporter disputes the significance of this finding because \"there isn’t very much of an opportunity to exploit this reliably for an information leak, so there isn’t any real security impact.\"","modified":"2026-07-08T22:15:02.494763Z","published":"2021-04-29T02:15:08.043Z","references":[{"type":"ADVISORY","url":"https://github.com/cesanta/mjs/releases/tag/1.26"},{"type":"FIX","url":"https://github.com/418sec/mjs/pull/2"},{"type":"EVIDENCE","url":"https://huntr.dev/bounties/1-other-mjs/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/418sec/mjs","events":[{"introduced":"30aa0f84dbb274afdd95006ed18431e131654cac"},{"last_affected":"30aa0f84dbb274afdd95006ed18431e131654cac"}],"database_specific":{"cpe":"cpe:2.3:a:cesanta:mongooseos_mjs:1.26:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.26"},{"last_affected":"1.26"}],"source":"CPE_STRING"}}],"versions":["1.26"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31875.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/cesanta/mjs","events":[{"introduced":"30aa0f84dbb274afdd95006ed18431e131654cac"},{"last_affected":"30aa0f84dbb274afdd95006ed18431e131654cac"},{"fixed":"30aa0f84dbb274afdd95006ed18431e131654cac"}],"database_specific":{"cpe":"cpe:2.3:a:cesanta:mongooseos_mjs:1.26:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.26"},{"last_affected":"1.26"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.26"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31875.json","vanir_signatures_modified":"2026-07-08T22:15:02Z","vanir_signatures":[{"digest":{"line_hashes":["234456157171672009667012020005863685987","146345927612699616111074413700893716313","108905283697329949653992095110269968398","40928701320816293082107573540797344185","16737667361413382403951905663352361970","32490330477822729405061052842574627060","164173215868758275743162668968896081187","336220235712481336989938226589175284337","320868728181603703685665517682974328720","27893539343358266705685645107797522834"],"threshold":0.9},"id":"CVE-2021-31875-6caf7cb9","signature_type":"Line","signature_version":"v1","source":"https://github.com/cesanta/mjs/commit/30aa0f84dbb274afdd95006ed18431e131654cac","target":{"file":"common/cs_varint.c"},"deprecated":false},{"source":"https://github.com/cesanta/mjs/commit/30aa0f84dbb274afdd95006ed18431e131654cac","target":{"file":"mjs.c","function":"cs_varint_decode"},"deprecated":false,"digest":{"length":389,"function_hash":"291219462004385368167517558065082996591"},"id":"CVE-2021-31875-7753ab29","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/cesanta/mjs/commit/30aa0f84dbb274afdd95006ed18431e131654cac","target":{"file":"common/cs_varint.c","function":"cs_varint_decode"},"deprecated":false,"digest":{"function_hash":"291219462004385368167517558065082996591","length":389},"id":"CVE-2021-31875-789e4ca9","signature_type":"Function"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/cesanta/mjs/commit/30aa0f84dbb274afdd95006ed18431e131654cac","target":{"file":"mjs.c"},"deprecated":false,"digest":{"line_hashes":["234456157171672009667012020005863685987","146345927612699616111074413700893716313","108905283697329949653992095110269968398","40928701320816293082107573540797344185","16737667361413382403951905663352361970","32490330477822729405061052842574627060","164173215868758275743162668968896081187","336220235712481336989938226589175284337","320868728181603703685665517682974328720","27893539343358266705685645107797522834"],"threshold":0.9},"id":"CVE-2021-31875-ebec0f7c"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}