CVE-2026-32874Patch(ultrajson_project / ultrajson)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ultrajson_project ultrajson systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1]) integers. The leaked memory is a copy of the string form of the integer plus an additional NULL byte. The leak occurs irrespective of whether the integer parses successfully or is rejected due to having more than sys.get_int_max_str_digits() digits, meaning that any sized leak per malicious JSON can be achieved provided that there is no limit on the overall size of the payload. Any service that calls ujson.load()/ujson.loads()/ujson.decode() on untrusted inputs is affected and vulnerable to denial of service attacks. This issue has been fixed in version 5.12.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-401CWE-772

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ultrajson

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-22); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
ultrajson

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-20: 1Mentions · 2026-03-22: 2Mentions · 2026-03-29: 1Patch / Workaround · 2026-03-22: 2Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 203-2003-2203-29
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-222
Patch2
2026-03-291
General1
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical Security Advisory for #Fedora 42: python-ujson 5.12.0 is out, fixing CVE-2026-32875 (buffer overflow DoS) and CVE-2026-32874 (memory leak). 🛡️ Read more: 👉 https://tinyurl.com/45nmxz5e #Security https://t.co/SbOKiKy3zS

    Post summary

    The advisory announces that Fedora 42 releases python‑ujson 5.12.0, which patches CVE‑2026‑32875 (a buffer overflow DoS) and CVE‑2026‑32874 (a memory leak), thereby mitigating these vulnerabilities.

    0001086
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32874 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSO… https://www.cve.org/CVERecord?id=CVE-2026-32874

    Post summary

    The post references CVE-2026-32874, describing an accumulating memory leak in UltraJSON 5.4.0–5.11.0, without mentioning PoC, exploit, active exploitation, patch, or false positive status.

    00010106
    56.8K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    General

    New resource for security engineers: Comprehensive pillar guide on the #python-ujson vulnerabilities (CVE-2026-32874/75). Read more: 👉 https://tinyurl.com/yvnnyr5y #Security https://t.co/AN1lBjCKTy

    Post summary

    The tweet promotes a link to a guide covering two new python‑ujson CVEs (CVE‑2026‑32874/75) but provides no additional technical info or evidence of active exploitation.

    0000056
    1.5K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Critical DoS flaws CVE-2026-32875 and CVE-2026-32874 in python-ujson affect Fedora 42-43. Fedora ships fixes in python-ujson 5.12.0. Users should update via dnf to mitigate DoS risk. #Linux https://threatcluster.io/cluster/critical-dos-vulnerabilities-in-python-ujson-affect-fedora-u-e00d9a25

    Post summary

    Fedora 42‑43 users face two critical DoS CVEs in python‑ujson; the vendor has released python‑ujson 5.12.0 which contains the fix, so updating via dnf mitigates the risk.

    0000031
    110 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appultrajson_projectultrajson-python-

Explore more