Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44660

Опубликовано: 27 мая 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation leaks the full size of the serialized payload. This vulnerability is fixed in 5.12.1.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ultrajson_project:ultrajson:*:*:*:*:*:python:*:*
Версия до 5.12.1 (исключая)

EPSS

Процентиль: 35%
0.00421
Низкий

7.5 High

CVSS3

Дефекты

CWE-401

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation leaks the full size of the serialized payload. This vulnerability is fixed in 5.12.1.

CVSS3: 7.5
redhat
2 месяца назад

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation leaks the full size of the serialized payload. This vulnerability is fixed in 5.12.1.

CVSS3: 7.5
debian
2 месяца назад

UltraJSON is a fast JSON encoder and decoder written in pure C with bi ...

CVSS3: 7.5
github
3 месяца назад

UltraJSON has a Memory Leak in ujson.dump() on Write Failure

EPSS

Процентиль: 35%
0.00421
Низкий

7.5 High

CVSS3

Дефекты

CWE-401