ujson has 6 CVEs on record between 2022 and 2026. The median CVSS is 7.5 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 2
Weakness classes
Products
- ujson 6
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2022-31116High· 7.5Incorrect handling of invalid surrogate pair characters42CVE-2026-44660High· 7.5UltraJSON has a Memory Leak in ujson.dump() on Write Failure41CVE-2026-32875High· 7.5UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop41CVE-2026-32874High· 7.5UltraJSON has a Memory Leak parsing large integers allows DoS 41CVE-2026-54911Medium· 6.5UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()36
ujson vulnerabilities
CVEs affecting ujson, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-54911Medium· 6.5UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
▾ Sunlitujson · ujsonEPSS 0.37%via OSV
CVE-2026-44660High· 7.5UltraJSON has a Memory Leak in ujson.dump() on Write Failure
UltraJSON has a Memory Leak in ujson.dump() on Write Failure
▾ Twilightujson · ujsonEPSS 0.42%via OSV
CVE-2026-32874High· 7.5UltraJSON has a Memory Leak parsing large integers allows DoS
UltraJSON has a Memory Leak parsing large integers allows DoS
▾ Twilightujson · ujsonEPSS 0.48%via OSV
CVE-2026-32875High· 7.5UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
▾ Twilightujson · ujsonEPSS 0.47%via OSV
CVE-2022-31116High· 7.5Incorrect handling of invalid surrogate pair characters
Incorrect handling of invalid surrogate pair characters
▾ Twilightujson · ujsonEPSS 2.6%via OSV
CVE-2022-31117Medium· 5.9Potential double free of buffer during string decoding
Potential double free of buffer during string decoding
▾ Sunlitujson · ujsonEPSS 1.9%via OSV