Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44660

Опубликовано: 27 мая 2026
Источник: debian
EPSS Низкий

Описание

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation leaks the full size of the serialized payload. This vulnerability is fixed in 5.12.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ujsonfixed5.13.0-1package
ujsonno-dsatrixiepackage
ujsonpostponedbookwormpackage
ujsonpostponedbullseyepackage

Примечания

  • https://github.com/ultrajson/ultrajson/security/advisories/GHSA-c38f-wx89-p2xg

  • Fixed by: https://github.com/ultrajson/ultrajson/commit/82af1d0ac01d09aa40c887b460d44b9d9f4bccd9 (5.12.1)

EPSS

Процентиль: 35%
0.00421
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation leaks the full size of the serialized payload. This vulnerability is fixed in 5.12.1.

CVSS3: 7.5
redhat
2 месяца назад

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation leaks the full size of the serialized payload. This vulnerability is fixed in 5.12.1.

CVSS3: 7.5
nvd
2 месяца назад

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation leaks the full size of the serialized payload. This vulnerability is fixed in 5.12.1.

suse-cvrf
5 дней назад

Security update for python-ujson

CVSS3: 7.5
github
3 месяца назад

UltraJSON has a Memory Leak in ujson.dump() on Write Failure

EPSS

Процентиль: 35%
0.00421
Низкий