CVE-2022-42227

HIGH

jsonlint 1.0 is vulnerable to heap-buffer-overflow via /home/hjsz/jsonlint/src/lexer.

Affects 2 products across 1 vendor.

CVSS 3.17.5
EPSS1.0%
Percentile61th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, no confidentiality impact, no integrity impact, full availability impact.
CWE Weakness Definitions
CWE-787: Out-of-Bounds Write

Software writes data past buffer boundaries, corrupting memory and potentially enabling code execution.

◆ AI Analysis — automated analysis, not human-reviewed

jsonlint 1.0 is vulnerable to a heap-buffer-overflow in the lexer component, which could allow an attacker to execute arbitrary code or cause a denial of service.

BSID: BS-2022-GLOBAL-064986-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2022-42227?
jsonlint 1.0 is vulnerable to a heap-buffer-overflow in the lexer component, which could allow an attacker to execute arbitrary code or cause a denial of service.
What is the CVSS score for CVE-2022-42227?
CVE-2022-42227 has CVSS 7.5 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. EPSS: 1.0%.
Is CVE-2022-42227 actively exploited?
No confirmed active exploitation of CVE-2022-42227 as of 2026-05-30.
How do I remediate CVE-2022-42227?
Priority: HIGH.
What systems are affected by CVE-2022-42227?
CVE-2022-42227 affects: Jsonlint Project, Jsonlint Project.
Vulnerability Details
CVE IDCVE-2022-42227
BSIDBS-2022-GLOBAL-064986-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published2022-10-19
Last Modified2025-05-08
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

jsonlint 1.0 is vulnerable to heap-buffer-overflow via /home/hjsz/jsonlint/src/lexer.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability occurs in the lexer component of jsonlint 1.0 when processing malformed JSON input. An attacker could exploit this by providing specially crafted JSON data to the application, leading to a heap-buffer-overflow.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductAffected Versions
Jsonlint Project Jsonlint C\+\+ —
Jsonlint Project Jsonlint C++ 1.0
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 1447 Days
CISA known-exploitedNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash092ca2c5af08a647097bac570afaeff93481d5994614b390effa8af04de84a1555f2f3a52c1670f6800114c999c92b849ecc0d41774b0e7d31a4301890bb32db

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.

Create a free account →