LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-32875

ultrajson project · ultrajson

Published
CVSS7.5
Severityhigh
WeaknessCWE-190
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer overflow or infinite loop through large indent handling. ujson.dumps() crashes the Python interpreter (segmentation fault) when the product of the indent parameter and the nested depth of the input exceeds INT32_MAX. It can also get stuck in an infinite loop if the indent is a large negative number. Both are caused by an integer overflow/underflow whilst calculating how much memory to reserve for indentation. And both can be used to achieve denial of service. To be vulnerable, a service must call ujson.dump()/ujson.dumps()/ujson.encode() whilst g

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32875

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32875.