Description:
CVE-2026-32874 ujson 5.4.0 to 5.11.0 inclusive contains an accumulating
memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1])
integers.
ujson 5.4.0 to 5.11.0 has an integer overflow while handling a large indent
which leads to a buffer overflow or infinite loop.
- https://bugs.mageia.org/show_bug.cgi?id=35258
- https://github.com/ultrajson/ultrajson/security/advisories/GHSA-wgvc-ghv9-3pmm
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3FAXR2DP4Q5GMDURV7CAFQ5YGYAOMVNL/
- https://www.cve.org/CVERecord?id=CVE-2026-32874
- https://www.cve.org/CVERecord?id=CVE-2026-32875
- 9/core/python-ujson-5.7.0-1.1.mga9
Get the latest Linux and open source security news straight to your inbox.