Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44660

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation leaks the full size of the serialized payload. This vulnerability is fixed in 5.12.1.

A flaw was found in UltraJSON, a fast JSON encoder and decoder. When the ujson.dump() function attempts to write data to a file-like object and an error occurs during this operation, the memory allocated for the serialized JSON string is not properly released. This continuous failure to deallocate memory can lead to a memory leak, potentially causing resource exhaustion and a Denial of Service (DoS) for the affected system.

Отчет

This Moderate flaw in UltraJSON can lead to a denial of service due to a memory leak when ujson.dump() attempts to write to a file-like object and encounters an exception. Applications utilizing ujson.dump() with attacker-controlled input or file-like objects are susceptible to resource exhaustion. Deployments that only use ujson.dumps() or JSON decoding functions are not affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Affected
Migration Toolkit for Applications 8mta/mta-generic-external-provider-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gaudi-rhel9Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/disk-image-cuda-rhel9Will not fix
Red Hat OpenShift AI (RHOAI)rhoai/odh-caikit-nlp-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-feature-server-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2482406python-ujson: UltraJSON: Memory leak leading to Denial of Service

EPSS

Процентиль: 35%
0.00421
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation leaks the full size of the serialized payload. This vulnerability is fixed in 5.12.1.

CVSS3: 7.5
nvd
2 месяца назад

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation leaks the full size of the serialized payload. This vulnerability is fixed in 5.12.1.

CVSS3: 7.5
debian
2 месяца назад

UltraJSON is a fast JSON encoder and decoder written in pure C with bi ...

suse-cvrf
5 дней назад

Security update for python-ujson

CVSS3: 7.5
github
3 месяца назад

UltraJSON has a Memory Leak in ujson.dump() on Write Failure

EPSS

Процентиль: 35%
0.00421
Низкий

7.5 High

CVSS3