ujson vulnerabilities
CVEs whose affected-version data names the ujson package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
CVE-2026-54911Medium· 6.5UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
▾ Sunlitujson · ujsonEPSS 0.37%via OSV
CVE-2026-44660High· 7.5UltraJSON has a Memory Leak in ujson.dump() on Write Failure
UltraJSON has a Memory Leak in ujson.dump() on Write Failure
▾ Twilightujson · ujsonEPSS 0.42%via OSV
CVE-2026-32874High· 7.5UltraJSON has a Memory Leak parsing large integers allows DoS
UltraJSON has a Memory Leak parsing large integers allows DoS
▾ Twilightujson · ujsonEPSS 0.48%via OSV
CVE-2026-32875High· 7.5UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
▾ Twilightujson · ujsonEPSS 0.47%via OSV
CVE-2022-31116High· 7.5Incorrect handling of invalid surrogate pair characters
Incorrect handling of invalid surrogate pair characters
▾ Twilightujson · ujsonEPSS 2.6%via OSV
CVE-2022-31117Medium· 5.9Potential double free of buffer during string decoding
Potential double free of buffer during string decoding
▾ Sunlitujson · ujsonEPSS 1.9%via OSV