cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
https://www.oracle.com/security-alerts/cpuoct2020.html
https://github.com/DaveGamble/cJSON/releases/tag/v1.7.11
https://github.com/DaveGamble/cJSON/issues/337
https://github.com/DaveGamble/cJSON/compare/c69134d...93688cb