Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 43 python-ujson Critical DoS Buffer Overflow 2026-bf741e26e4

fedora
Calendar Grey March 22, 2026
Dist Fedora Esm H88
Fedora 43 python-ujson update fixes buffer overflow and addresses DoS vulnerabilities for improved performance.
Update to 5.12.0

Summary

UltraJSON is an ultra fast JSON encoder and decoder written in pure C with

bindings for Python.

Update Information:

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

Change Log

* Thu Mar 12 2026 Benjamin A. Beasley - 5.12.0-1 - Update to 5.12.0 (close RHBZ#2446884) * Thu Mar 12 2026 Benjamin A. Beasley - 5.11.0-9 - Use the provisional pyproject declarative buildsystem * Thu Mar 12 2026 Benjamin A. Beasley - 5.11.0-6 - Use a pkgconfig(\u2026) BR on double-conversion * Sat Jan 17 2026 Fedora Release Engineering - 5.11.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

References


[ 1 ] Bug #2446884 - python-ujson-5.12.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2446884 [ 2 ] Bug #2449473 - CVE-2026-32875 python-ujson: UltraJSON: Denial of Service via large indent parameter in JSON serialization [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2449473 [ 3 ] Bug #2449474 - CVE-2026-32874 python-ujson: UltraJSON: Denial of Service due to memory leak when parsing large integers [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2449474

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bf741e26e4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: python-ujson
Product: Fedora 43
Version: 5.12.0
Release: 1.fc43
Summary: Ultra fast JSON encoder and decoder written in pure C

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here