---
id: CVE-2026-44660
title: >-
  python-ujson: UltraJSON: Memory leak leading to Denial of Service
  (CVE-2026-44660)
summary: >-
  A flaw was found in UltraJSON, a fast JSON encoder and decoder. When the
  `ujson.dump()` function attempts to write data to a file-like object and an
  error occurs during this operation, the memory allocated for the serialized
  JSON string is…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-772
vendor: Red Hat
product: Red Hat OpenShift AI 3.4
affected:
  - exploit_intelligence
  - migration_toolkit_for_applications 8
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - openshift_ai 2.25
  - openshift_ai 3.4
  - satellite 6.18
  - satellite 6.19
patched:
  - openshift_ai 2.25
  - openshift_ai 3.4
  - satellite 6.18
  - satellite 6.19
published: '2026-05-27'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:24:53+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44660.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44660.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-44660'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2482406'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-44660'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44660'
  - url: >-
      https://github.com/ultrajson/ultrajson/commit/82af1d0ac01d09aa40c887b460d44b9d9f4bccd9
  - url: 'https://github.com/ultrajson/ultrajson/releases/tag/5.12.1'
  - url: >-
      https://github.com/ultrajson/ultrajson/security/advisories/GHSA-c38f-wx89-p2xg
  - url: 'https://access.redhat.com/errata/RHSA-2026:42644'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:51347'
  - url: 'https://access.redhat.com/errata/RHSA-2026:51195'
  - url: 'https://github.com/ultrajson/ultrajson'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00644
epssPercentile: 0.48602
aliases:
  - GHSA-c38f-wx89-p2xg
  - PYSEC-2026-2293
ecosystem: pip
ingestedAt: '2026-07-13T18:57:56.211Z'
---

## Overview

A flaw was found in UltraJSON, a fast JSON encoder and decoder. When the `ujson.dump()` function attempts to write data to a file-like object and an error occurs during this operation, the memory allocated for the serialized JSON string is not properly released. This continuous failure to deallocate memory can lead to a memory leak, potentially causing resource exhaustion and a Denial of Service (DoS) for the affected system.

## Vendor advisories

- **RHSA-2026:42644** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-07-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:42644)
- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)
- **RHSA-2026:51347** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51347)
- **RHSA-2026:51195** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51195)
- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat Enterprise Linux AI (RHEL AI) 3, Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat OpenShift AI (RHOAI) · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44660.json)

**python-ujson: UltraJSON: Memory leak leading to Denial of Service** — rated Moderate by Red Hat. Released 2026-05-27, updated 2026-09-23.

Affected:

- Exploit Intelligence
- Migration Toolkit for Applications 8
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)

Fixed:

- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4
- Red Hat Satellite 6.18
- Red Hat Satellite 6.19

No fix planned:

- Red Hat Enterprise Linux AI (RHEL AI) 3
- Exploit Intelligence
- Migration Toolkit for Applications 8
- Red Hat OpenShift AI (RHOAI)

Not affected:

- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat OpenStack Platform 18.0

## Remediation

For Red Hat OpenShift AI 2.25.9 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:42644
For Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:60520
For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:51347

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-44660)

Affected packages:

- `ujson < 5.12.1`

Patched in:

- `ujson 5.12.1`

Source: https://osv.dev/vulnerability/GHSA-c38f-wx89-p2xg
