An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
{
"cpes": [
"cpe:2.3:a:json-c_project:json-c:0.15-20200726:*:*:*:*:*:*:*"
],
"severity": "Critical"
}