LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-44660

ultrajson project · ultrajson

Published
CVSS7.5
Severityhigh
WeaknessCWE-401
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation leaks the full size of the serialized payload. This vulnerability is fixed in 5.12.1.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-44660

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-44660.