CVE-2026-32874
published 2026-03-20CVE-2026-32874: UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.48%
38.8th percentile
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1]) integers. The leaked memory is a copy of the string form of the integer plus an additional NULL byte. The leak occurs irrespective of whether the integer parses successfully or is rejected due to having more than sys.get_int_max_str_digits() digits, meaning that any sized leak per malicious JSON can be achieved provided that there is no limit on the overall size of the payload. Any service that calls ujson.load()/ujson.loads()/ujson.decode() on untrusted inputs is affected and vulnerable to denial of service attacks. This issue has been fixed in version 5.12.0.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ujson | — | — |
| ubuntu | ujson | — | — |
| ultrajson | ultrajson | — | — |
| ultrajson_project | ultrajson | >= 5.4.0 < 5.12.0 | 5.12.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-32874: UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3
osv·2026-03-20·CVSS 7.5
CVE-2026-32874 [HIGH] CVE-2026-32874: UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1]) integers. The leaked memory is a copy of the string form of the integer plus an additional NULL byte. The leak occurs irrespective of whether the integer parses successfully or is rejected due to having more than sys.get_int_max_str_digits() digits, meaning that any sized leak per malicious JSON can be achieved provided that there is no limit on the overall size of the payload. Any service that calls ujson.load()/ujson.loads()/ujson.decode() on untrusted inputs is affected and vulnerable to denial of service attacks. This issue has been fixed in version 5.12.0.
GHSA
UltraJSON has a Memory Leak parsing large integers allows DoS
ghsa·2026-03-18
CVE-2026-32874 [HIGH] CWE-401 UltraJSON has a Memory Leak parsing large integers allows DoS
UltraJSON has a Memory Leak parsing large integers allows DoS
#### Summary
ujson 5.4.0 to 5.11.0 inclusive contain an accumulating memory leak in JSON parsing _large_ (outside of the range [-2^63, 2^64 - 1]) integers.
#### Exploitability
Any service that calls `ujson.load()`/`ujson.loads()`/`ujson.decode()` on untrusted inputs is affected and vulnerable to denial of service attacks.
#### Details
The leaked memory is a copy of the string form of the integer plus an additional NULL byte. The leak occurs irrespective of whether the integer parses successfully or is rejected due to having more than `sys.get_int_max_str_digits()` digits, meaning that any sized leak per malicious JSON can be achieved provided that there is no limit on the overall size of the payload.
```python
ujson.loads
OSV
UltraJSON has a Memory Leak parsing large integers allows DoS
osv·2026-03-18
CVE-2026-32874 [HIGH] UltraJSON has a Memory Leak parsing large integers allows DoS
UltraJSON has a Memory Leak parsing large integers allows DoS
#### Summary
ujson 5.4.0 to 5.11.0 inclusive contain an accumulating memory leak in JSON parsing _large_ (outside of the range [-2^63, 2^64 - 1]) integers.
#### Exploitability
Any service that calls `ujson.load()`/`ujson.loads()`/`ujson.decode()` on untrusted inputs is affected and vulnerable to denial of service attacks.
#### Details
The leaked memory is a copy of the string form of the integer plus an additional NULL byte. The leak occurs irrespective of whether the integer parses successfully or is rejected due to having more than `sys.get_int_max_str_digits()` digits, meaning that any sized leak per malicious JSON can be achieved provided that there is no limit on the overall size of the payload.
```python
ujson.loads
Ubuntu
UltraJSON vulnerabilities
vendor_ubuntu·2026-04-28·CVSS 7.5
CVE-2026-32875 [HIGH] UltraJSON vulnerabilities
Title: UltraJSON vulnerabilities
Summary: Several security issues were fixed in UltraJSON.
Cameron Criswell discovered that UltraJSON contained a memory leak
that would occur when parsing large integers. An attacker could
possibly use this issue to cause UltraJSON to crash, resulting in a
denial of service. This issue only affected Ubuntu 24.04 LTS,
Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-32874)
It was discovered that UltraJSON contained integer overflow/underflow
issues when calculating how much memory to reserve for indentation in
certain instances. An attacker could possibly use this issue to cause
UltraJSON to crash, resulting in a denial of service. (CVE-2026-32875)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
UltraJSON: UltraJSON: Denial of Service due to memory leak when parsing large integers
vendor_redhat·2026-03-20·CVSS 7.5
CVE-2026-32874 [HIGH] CWE-772 UltraJSON: UltraJSON: Denial of Service due to memory leak when parsing large integers
UltraJSON: UltraJSON: Denial of Service due to memory leak when parsing large integers
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1]) integers. The leaked memory is a copy of the string form of the integer plus an additional NULL byte. The leak occurs irrespective of whether the integer parses successfully or is rejected due to having more than sys.get_int_max_str_digits() digits, meaning that any sized leak per malicious JSON can be achieved provided that there is no limit on the overall size of the payload. Any service that calls ujson.load()/ujson.loads()/ujson.decode() on untrusted inputs is affected and vulnera
Debian
CVE-2026-32874: ujson - UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for...
vendor_debian·2026·CVSS 7.5
CVE-2026-32874 [HIGH] CVE-2026-32874: ujson - UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for...
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1]) integers. The leaked memory is a copy of the string form of the integer plus an additional NULL byte. The leak occurs irrespective of whether the integer parses successfully or is rejected due to having more than sys.get_int_max_str_digits() digits, meaning that any sized leak per malicious JSON can be achieved provided that there is no limit on the overall size of the payload. Any service that calls ujson.load()/ujson.loads()/ujson.decode() on untrusted inputs is affected and vulnerable to denial of service attacks. This issue has been fixed in version 5.12.0.
Scope: lo
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-32874 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-32874 [HIGH] CVE-2026-32874 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32874 :
Python vulnerability analysis and mitigation
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1]) integers. The leaked memory is a copy of the string form of the integer plus an additional NULL byte. The leak occurs irrespective of whether the integer parses successfully or is rejected due to having more than sys.get_int_max_str_digits() digits, meaning that any sized leak per malicious JSON can be achieved provided that there is no limit on the overall size of the payload. Any service that calls ujson.load()/ujson.loads()/ujson.decode() on untrusted inputs is affected and vulnerable to denial of serv
Bugzilla
CVE-2026-32874 UltraJSON: UltraJSON: Denial of Service due to memory leak when parsing large integers
bugzilla·2026-03-20·CVSS 7.5
CVE-2026-32874 [HIGH] CVE-2026-32874 UltraJSON: UltraJSON: Denial of Service due to memory leak when parsing large integers
CVE-2026-32874 UltraJSON: UltraJSON: Denial of Service due to memory leak when parsing large integers
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1]) integers. The leaked memory is a copy of the string form of the integer plus an additional NULL byte. The leak occurs irrespective of whether the integer parses successfully or is rejected due to having more than sys.get_int_max_str_digits() digits, meaning that any sized leak per malicious JSON can be achieved provided that there is no limit on the overall size of the payload. Any service that calls ujson.load()/ujson.loads()/ujson.decode() on untrusted inputs is affec
https://github.com/ultrajson/ultrajson/commit/4baeb950df780092bd3c89fc702a868e99a3a1d2https://github.com/ultrajson/ultrajson/releases/tag/5.12.0https://github.com/ultrajson/ultrajson/security/advisories/GHSA-wgvc-ghv9-3pmmhttps://access.redhat.com/security/cve/CVE-2026-32874https://bugzilla.redhat.com/show_bug.cgi?id=2449411https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32874.json
2026-03-20
Published