A vulnerability was found in DaveGamble cJSON 1.7.19. It has been declared as critical. This affects the function print_string_ptr of the file cJSON.c. Such manipulation leads to integer overflow.

This vulnerability is documented as CVE-2026-16554. The attack can be executed remotely. There is not any exploit available.