CVE-2026-32875Disclosure(ultrajson_project / ultrajson)

LOWCVSS 7.5 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch ultrajson_project ultrajson systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer overflow or infinite loop through large indent handling. ujson.dumps() crashes the Python interpreter (segmentation fault) when the product of the indent parameter and the nested depth of the input exceeds INT32_MAX. It can also get stuck in an infinite loop if the indent is a large negative number. Both are caused by an integer overflow/underflow whilst calculating how much memory to reserve for indentation. And both can be used to achieve denial of service. To be vulnerable, a service must call ujson.dump()/ujson.dumps()/ujson.encode() whilst giving untrusted users control over the indent parameter and not restrict that indentation to reasonably small non-negative values. A service may also be vulnerable to the infinite loop if it uses a fixed negative indent. An underflow always occurs for any negative indent when the input data is at least one level nested but, for small negative indents, the underflow is usually accidentally rectified by another overflow. This issue has been fixed in version 5.12.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190CWE-787CWE-835

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ultrajson

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-03-22)
  • 6 total mentions across 3 days

Affected systems

Products
ultrajson

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-19: 1Mentions · 2026-03-20: 1Mentions · 2026-03-22: 4Patch / Workaround · 2026-03-22: 2Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 403-1903-2003-22
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-191
General1
2026-03-201
Disclosure1
2026-03-224
Disclosure2Patch2
Full discourse6 posts
  • celeste@vmfunc
    General

    CVE-2026-32875 <3

    Post summary

    The post merely references CVE-2026-32875 without providing any supporting details.

    210119933.1K
    23.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical Security Advisory for #Fedora 42: python-ujson 5.12.0 is out, fixing CVE-2026-32875 (buffer overflow DoS) and CVE-2026-32874 (memory leak). 🛡️ Read more: 👉 https://tinyurl.com/45nmxz5e #Security https://t.co/SbOKiKy3zS

    Post summary

    The advisory announces that python‑ujson 5.12.0 release addresses CVE‑2026‑32875 (buffer overflow DoS) and CVE‑2026‑32874 (memory leak).

    0001086
    1.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `UltraJSON` is vulnerable to an integer overflow (CVE-2026-32875) when handling large indent values, potentially leading to buffer overflow or infinite loop. Review usage. #infosec #json #security https://www.pulsepatch.io/posts/cve-2026-32875-ultrajson-integer-overflow

    Post summary

    UltraJSON has a CVE-2026-32875 integer overflow that can trigger buffer overflows or infinite loops with large indent values; no exploitation evidence or patch info is provided.

    0000027
    2 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    #Fedora 43 users: A critical buffer overflow vulnerability (CVE-2026-32875) has been found in python-ujson. If you're a developer, this is a MUST-FIX. Read more: 👉 https://tinyurl.com/5825xtrz #Security https://t.co/aNvow6NDhY

    Post summary

    The tweet announces a critical buffer overflow vulnerability (CVE‑2026‑32875) in python‑ujson for Fedora 43, urging developers to fix it while linking to a resource for more details.

    0000087
    1.5K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Critical DoS flaws CVE-2026-32875 and CVE-2026-32874 in python-ujson affect Fedora 42-43. Fedora ships fixes in python-ujson 5.12.0. Users should update via dnf to mitigate DoS risk. #Linux https://threatcluster.io/cluster/critical-dos-vulnerabilities-in-python-ujson-affect-fedora-u-e00d9a25

    Post summary

    The post announces that critical DoS vulnerabilities in python‑ujson (CVE‑2026‑32875 & CVE‑2026‑32874) affect Fedora 42‑43 and that users should update to python‑ujson 5.12.0 to mitigate the risk.

    0000031
    110 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32875 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer overflow or infini… https://www.cve.org/CVERecord?id=CVE-2026-32875

    Post summary

    The text announces a buffer overflow vulnerability in UltraJSON (CVE-2026-32875) affecting versions 5.10 to 5.11.0, with no PoC, exploit, or mitigation details provided.

    0000078
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appultrajson_projectultrajson-python-

Explore more