CVE-2026-32874 describes an accumulating memory leak in UltraJSON versions 5.4.0 through 5.11.0, impacting services that parse untrusted JSON inputs containing large integers. This vulnerability, with a CVSS score of 7.5 (High), allows a remote attacker to trigger a denial of service through memory exhaustion with low attack complexity. The leak occurs irrespective of parsing success, meaning any sized leak can be achieved per malicious JSON payload. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.4.0, < 5.12.0CPE matchmatch criteria | cpe:2.3:a:ultrajson_project:ultrajson:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.