VendorsUltraJSON Projectultrajsonany version
Vulnerabilities

UltraJSON Project UltraJSON any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2026-44660
UltraJSON: Memory Leak in ujson.dump() on Write Failure
Published 2026-05-27 · Analyzed
8.7EPSS 0.004
CVE-2022-31116
Incorrect handling of invalid surrogate pair characters in ujson
Published 2022-07-05 · Modified
7.5EPSS 0.026
CVE-2026-32874
UltraJSON has a Memory Leak parsing large integers allows DoS
Published 2026-03-20 · Modified
7.5EPSS 0.005
CVE-2026-32875
UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
Published 2026-03-20 · Modified
7.5EPSS 0.005
CVE-2026-54911
UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
Published 2026-06-22 · Analyzed
6.5EPSS 0.004
CVE-2022-31117
Double free of buffer during string decoding in ujson
Published 2022-07-05 · Modified
5.9EPSS 0.019
CVE-2021-45958
UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
Published 2021-12-31 · Modified
5.5EPSS 0.016